File name:

FlexGridService_exe.zip

Full analysis: https://app.any.run/tasks/6d6e1798-eb2f-4300-ab4a-55875918042a
Verdict: Malicious activity
Threats:

Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email.

Analysis date: September 09, 2020, 06:34:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

9D2E4ABE608FB429F161D66912BC90F9

SHA1:

F94082548F7BA2A9A4B767DB4C0CB410E18DDB88

SHA256:

65E9FBDA7C9D47C1062623C8AFB4558AF70A2EEB9DFDF853DC5D569D1663FA26

SSDEEP:

49152:iH0Sq/Kskx9pTBCw5agvaRq3LnWo+LKUjsm8H:iUtCssHYfRqDWHZts

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • FlexGridService.exe (PID: 2544)
      • FlexGridService.exe (PID: 2628)
    • Connects to CnC server

      • FlexGridService.exe (PID: 2628)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2920)
      • FlexGridService.exe (PID: 2544)
    • Creates files in the program directory

      • FlexGridService.exe (PID: 2544)
      • FlexGridService.exe (PID: 2628)
    • Reads Internet Cache Settings

      • FlexGridService.exe (PID: 2628)
  • INFO

    • Reads the hosts file

      • FlexGridService.exe (PID: 2628)
    • Manual execution by user

      • cmd.exe (PID: 3320)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: 0x0001
ZipCompression: None
ZipModifyDate: 2020:09:09 06:32:06
ZipCRC: 0x04f7b5a9
ZipCompressedSize: 2018316
ZipUncompressedSize: 2018316
ZipFileName: FlexGridService.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start winrar.exe flexgridservice.exe cmd.exe no specs flexgridservice.exe

Process information

PID
CMD
Path
Indicators
Parent process
2544"C:\Users\admin\AppData\Local\Temp\Rar$EXb2920.15324\FlexGridService.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb2920.15324\FlexGridService.exe
WinRAR.exe
User:
admin
Company:
High Criteria inc.
Integrity Level:
MEDIUM
Description:
Total Recorder (Professional Edition)
Exit code:
0
Version:
7.6.2.19
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb2920.15324\flexgridservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2628FlexGridService.exe /CC:\Users\admin\Desktop\FlexGridService.exe
cmd.exe
User:
admin
Company:
High Criteria inc.
Integrity Level:
MEDIUM
Description:
Total Recorder (Professional Edition)
Exit code:
0
Version:
7.6.2.19
Modules
Images
c:\users\admin\desktop\flexgridservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2920"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\FlexGridService_exe.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3320"cmd.exe" /s /k pushd "C:\Users\admin\Desktop"C:\Windows\system32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
493
Read events
458
Write events
35
Delete events
0

Modification events

(PID) Process:(2920) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2920) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2920) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\139\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2920) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\139\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(2920) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\FlexGridService_exe.zip
(PID) Process:(2920) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2920) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2920) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2920) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2920) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
Executable files
2
Suspicious files
1
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
2920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2920.19696\FlexGridService.exe
MD5:
SHA256:
2628FlexGridService.exeC:\ProgramData\ts.dattext
MD5:
SHA256:
2628FlexGridService.exeC:\ProgramData\irw.atsdtext
MD5:A54F0041A9E15B050F25C463F1DB7449
SHA256:AD95131BC0B799C0B1AF477FB14FCF26A6A9F76079E48BF090ACB7E8367BFD0E
2628FlexGridService.exeC:\ProgramData\rc.datbinary
MD5:4352D88A78AA39750BF70CD6F27BCAA5
SHA256:67ABDD721024F0FF4E0B3F4C2FC13BC5BAD42D0B7851D456D88D203D15AAA450
2544FlexGridService.exeC:\ProgramData\FlexGridService\FlexGridService.exeexecutable
MD5:16802B401E1B23432FE14FA6F32615D0
SHA256:3A24F692E6B1A99D574641F253653034BBDF5ACF908C4859975D27EEF8FB1C93
2920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2920.15324\FlexGridService.exeexecutable
MD5:16802B401E1B23432FE14FA6F32615D0
SHA256:3A24F692E6B1A99D574641F253653034BBDF5ACF908C4859975D27EEF8FB1C93
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
2
DNS requests
1
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2628
FlexGridService.exe
GET
200
185.141.63.172:80
http://egsjbei.ua/single.php?c=94bf3661c794e3eb1ba46c008930ec68d80a3eec48a792c6c460983d96725657a011e5d2855f6c1fae6fce8bd311a185a1071450d55da71ab9d802362b5b018b84f55cdeec9df9e518b0cbf1e15fff98a82f6b83ddde
unknown
text
14 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2628
FlexGridService.exe
163.172.91.242:53
Online S.a.s.
FR
unknown
2628
FlexGridService.exe
185.141.63.172:80
egsjbei.ua
malicious

DNS requests

Domain
IP
Reputation
egsjbei.ua
  • 185.141.63.172
malicious

Threats

PID
Process
Class
Message
2628
FlexGridService.exe
A Network Trojan was detected
ET INFO Suspicious Windows NT version 9 User-Agent
1 ETPRO signatures available at the full report
No debug info