URL:

https://www.proxifier.com/download/ProxifierPE.zip

Full analysis: https://app.any.run/tasks/ba7bd014-9e8f-4140-a079-3968329a16ac
Verdict: Malicious activity
Analysis date: August 18, 2021, 22:31:37
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

A00F61587439CB4D6119A6608E5E2EBC

SHA1:

FFBE043A4464B790D707E443896023BC56A9CE0B

SHA256:

5E2AC1C0EC21C71677B458B5A198B820385DE74DB96224A23B5E49A1C2564F21

SSDEEP:

3:N8DSLodMQyZMLdnhqMVn:2OLpQyZMhhqUn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3716)
      • Proxifier.exe (PID: 3108)
      • Explorer.EXE (PID: 1724)
      • ctfmon.exe (PID: 1488)
      • DllHost.exe (PID: 2340)
      • DllHost.exe (PID: 3632)
      • Proxifier.exe (PID: 3992)
      • ProxyChecker.exe (PID: 3268)
      • DllHost.exe (PID: 3736)
      • DllHost.exe (PID: 1036)
      • Proxifier.exe (PID: 3812)
      • Proxifier.exe (PID: 424)
    • Application was dropped or rewritten from another process

      • Proxifier.exe (PID: 3108)
      • Proxifier.exe (PID: 3812)
      • Proxifier.exe (PID: 1868)
      • Proxifier.exe (PID: 2908)
      • ProxyChecker.exe (PID: 3268)
      • Proxifier.exe (PID: 2384)
      • Proxifier.exe (PID: 3992)
      • Proxifier.exe (PID: 424)
  • SUSPICIOUS

    • Starts Internet Explorer

      • Explorer.EXE (PID: 1724)
    • Checks supported languages

      • WinRAR.exe (PID: 3144)
      • Proxifier.exe (PID: 3108)
      • Proxifier.exe (PID: 3812)
      • Proxifier.exe (PID: 1868)
      • ProxyChecker.exe (PID: 3268)
      • Proxifier.exe (PID: 2908)
      • Proxifier.exe (PID: 3992)
      • Proxifier.exe (PID: 2384)
      • Proxifier.exe (PID: 424)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 3144)
    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 3056)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3144)
    • Reads the computer name

      • WinRAR.exe (PID: 3144)
      • Proxifier.exe (PID: 3108)
      • Proxifier.exe (PID: 3812)
      • Proxifier.exe (PID: 3992)
      • Proxifier.exe (PID: 424)
    • Uses IPCONFIG.EXE to discover IP address

      • Proxifier.exe (PID: 3108)
      • Proxifier.exe (PID: 3812)
      • Proxifier.exe (PID: 3992)
      • Proxifier.exe (PID: 424)
  • INFO

    • Reads the computer name

      • iexplore.exe (PID: 2320)
      • iexplore.exe (PID: 3056)
      • ipconfig.exe (PID: 3764)
      • ipconfig.exe (PID: 3656)
      • DllHost.exe (PID: 2340)
      • DllHost.exe (PID: 3632)
      • ipconfig.exe (PID: 1988)
      • ipconfig.exe (PID: 2056)
      • DllHost.exe (PID: 3736)
      • DllHost.exe (PID: 1036)
      • ipconfig.exe (PID: 660)
    • Application launched itself

      • iexplore.exe (PID: 2320)
    • Checks supported languages

      • iexplore.exe (PID: 2320)
      • iexplore.exe (PID: 3056)
      • DllHost.exe (PID: 2340)
      • ipconfig.exe (PID: 3656)
      • ipconfig.exe (PID: 3764)
      • DllHost.exe (PID: 3632)
      • ipconfig.exe (PID: 1988)
      • ipconfig.exe (PID: 2056)
      • DllHost.exe (PID: 3736)
      • DllHost.exe (PID: 1036)
      • ipconfig.exe (PID: 660)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 3056)
    • Changes internet zones settings

      • iexplore.exe (PID: 2320)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 2320)
    • Reads the date of Windows installation

      • iexplore.exe (PID: 2320)
    • Checks Windows Trust Settings

      • iexplore.exe (PID: 2320)
      • iexplore.exe (PID: 3056)
    • Manual execution by user

      • Proxifier.exe (PID: 3108)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
62
Monitored processes
23
Malicious processes
6
Suspicious processes
6

Behavior graph

Click at the process to see the details
start iexplore.exe no specs iexplore.exe winrar.exe searchprotocolhost.exe no specs proxifier.exe ipconfig.exe no specs ipconfig.exe no specs explorer.exe no specs ctfmon.exe no specs WinInetBrokerServer no specs Thumbnail Cache Class Factory for Out of Proc Server no specs proxifier.exe no specs ipconfig.exe no specs proxifier.exe no specs proxifier.exe no specs ipconfig.exe no specs proxychecker.exe no specs proxifier.exe no specs Thumbnail Cache Class Factory for Out of Proc Server no specs Thumbnail Cache Class Factory for Out of Proc Server no specs proxifier.exe no specs proxifier.exe no specs ipconfig.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
424"C:\Users\admin\Desktop\Proxifier PE\Proxifier.exe" C:\Users\admin\Desktop\Proxifier PE\Proxifier.exeExplorer.EXE
User:
admin
Company:
Initex
Integrity Level:
MEDIUM
Description:
Proxifier Portable Edition v4.05
Exit code:
0
Version:
4.5.0.1
Modules
Images
c:\users\admin\desktop\proxifier pe\proxifier.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
660ipconfig /flushdnsC:\Windows\system32\ipconfig.exeProxifier.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
IP Configuration Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ipconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
1036C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}C:\Windows\system32\DllHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\dllhost.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1488C:\Windows\System32\ctfmon.exe C:\Windows\System32\ctfmon.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
CTF Loader
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ctfmon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msctfmonitor.dll
c:\windows\system32\msctf.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1724C:\Windows\Explorer.EXEC:\Windows\Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1868"C:\Users\admin\Desktop\Proxifier PE\Proxifier.exe" C:\Users\admin\Desktop\Proxifier PE\Proxifier.exeExplorer.EXE
User:
admin
Company:
Initex
Integrity Level:
MEDIUM
Description:
Proxifier Portable Edition v4.05
Exit code:
0
Version:
4.5.0.1
Modules
Images
c:\users\admin\desktop\proxifier pe\proxifier.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msimg32.dll
1988ipconfig /flushdnsC:\Windows\system32\ipconfig.exeProxifier.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
IP Configuration Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ipconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
2056ipconfig /flushdnsC:\Windows\system32\ipconfig.exeProxifier.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
IP Configuration Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ipconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
2320"C:\Program Files\Internet Explorer\iexplore.exe" "https://www.proxifier.com/download/ProxifierPE.zip"C:\Program Files\Internet Explorer\iexplore.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2340C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}C:\Windows\system32\DllHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
Total events
20 070
Read events
19 842
Write events
226
Delete events
2

Modification events

(PID) Process:(2320) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(2320) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(2320) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30905472
(PID) Process:(2320) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(2320) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30905472
(PID) Process:(2320) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2320) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2320) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2320) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2320) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
5
Suspicious files
9
Text files
3
Unknown types
10

Dropped files

PID
Process
Filename
Type
3056iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:
SHA256:
3056iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850Dbinary
MD5:
SHA256:
3056iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\4FADE0FBA8B4B9B6F921D91DF8F055F4der
MD5:
SHA256:
3056iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\4FADE0FBA8B4B9B6F921D91DF8F055F4binary
MD5:
SHA256:
3056iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850Dder
MD5:
SHA256:
3056iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\ProxifierPE.zip.jxr3cgh.partialcompressed
MD5:
SHA256:
3056iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:F7DCB24540769805E5BB30D193944DCE
SHA256:6B88C6AC55BBD6FEA0EBE5A760D1AD2CFCE251C59D0151A1400701CB927E36EA
3056iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\ProxifierPE[1].zipcompressed
MD5:
SHA256:
2320iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFED54E20899D64402.TMPgmc
MD5:
SHA256:
2320iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{16D4F915-0074-11EC-A146-12A9866C77DE}.datbinary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
7
DNS requests
10
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1672
svchost.exe
GET
304
2.16.186.26:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?1395118fe308ea05
unknown
whitelisted
3056
iexplore.exe
GET
200
151.139.128.14:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D
US
der
727 b
whitelisted
3056
iexplore.exe
GET
200
151.139.128.14:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEEzBwyAEHuJde9BwAym%2BzLs%3D
US
der
471 b
whitelisted
3108
Proxifier.exe
GET
200
172.104.17.238:80
http://www.proxifier.com/distr/last_versions/ProxifierPortable4/40501/?nocache=8A9C2D5A8A9C2D5AA5A17A80
US
text
46 b
suspicious
3056
iexplore.exe
GET
200
2.16.186.26:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?cc400e3b380bef51
unknown
compressed
4.70 Kb
whitelisted
1672
svchost.exe
GET
304
2.16.186.26:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?0968e9df1e2aec06
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3108
Proxifier.exe
172.104.17.238:80
www.proxifier.com
Linode, LLC
US
suspicious
1672
svchost.exe
2.16.186.26:80
ctldl.windowsupdate.com
Akamai International B.V.
whitelisted
3056
iexplore.exe
172.104.17.238:443
www.proxifier.com
Linode, LLC
US
suspicious
3056
iexplore.exe
2.16.186.26:80
ctldl.windowsupdate.com
Akamai International B.V.
whitelisted
3056
iexplore.exe
151.139.128.14:80
ocsp.usertrust.com
Highwinds Network Group, Inc.
US
suspicious

DNS requests

Domain
IP
Reputation
www.proxifier.com
  • 172.104.17.238
suspicious
ctldl.windowsupdate.com
  • 2.16.186.26
  • 2.16.186.33
  • 2.16.186.25
whitelisted
ocsp.usertrust.com
  • 151.139.128.14
whitelisted
ocsp.sectigo.com
  • 151.139.128.14
whitelisted
iana.org
  • 192.0.43.8
unknown

Threats

No threats detected
No debug info