File name:

μProxy Tool 1.81.rar

Full analysis: https://app.any.run/tasks/501168a7-d9f5-4ca3-b6ac-0ecd97e8798d
Verdict: Malicious activity
Analysis date: December 22, 2018, 11:45:53
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

77508080104B987900C03C2E7308D6BD

SHA1:

0C4ED4ED961A679BC5144AAF8A7380BFCBFD9CD2

SHA256:

6FF741A295FA8C167C139DF1673C7340D965397261751F380E037C8B01939B83

SSDEEP:

12288:oEq8IJRaOn5F7a6ElBHxw5ZXwRtiRi1eklQ/cogl2Y0/FCjYWImoemh2NJ:nqr5Tc58MtiRn0odictemh2NJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • μProxy Tool.exe (PID: 3128)
  • SUSPICIOUS

    • Connects to unusual port

      • μProxy Tool.exe (PID: 3128)
  • INFO

    • Reads settings of System Certificates

      • μProxy Tool.exe (PID: 3128)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 605612
UncompressedSize: 727552
OperatingSystem: Win32
ModifyDate: 2018:04:01 00:57:25
PackingMethod: Normal
ArchivedFileName: ?Proxy Tool.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
31
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs μproxy tool.exe

Process information

PID
CMD
Path
Indicators
Parent process
2836"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\μProxy Tool 1.81.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
3128"C:\Users\admin\Desktop\μProxy Tool.exe" C:\Users\admin\Desktop\μProxy Tool.exe
explorer.exe
User:
admin
Company:
Nikola Тesla
Integrity Level:
MEDIUM
Description:
Proxy Tool
Exit code:
0
Version:
1.81
Modules
Images
c:\users\admin\desktop\μproxy tool.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
500
Read events
470
Write events
30
Delete events
0

Modification events

(PID) Process:(2836) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2836) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2836) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2836) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\μProxy Tool 1.81.rar
(PID) Process:(2836) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2836) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2836) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2836) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3128) μProxy Tool.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\µProxy Tool_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3128) μProxy Tool.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\µProxy Tool_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
0
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2836WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2836.19187\μProxy Tool.exe
MD5:
SHA256:
2836WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2836.19187\Data\Source\HttpSource.txt
MD5:
SHA256:
2836WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2836.19187\Data\Source\SocksSource.txt
MD5:
SHA256:
3128μProxy Tool.exeC:\Users\admin\Desktop\Data\Proxies\Scraped_Proxies.txttext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
65
TCP/UDP connections
190
DNS requests
20
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3128
μProxy Tool.exe
GET
172.217.18.19:80
http://www.proxyserverlist24.top/feeds/posts/default
US
whitelisted
3128
μProxy Tool.exe
GET
301
104.27.146.242:80
http://free-proxy-list.net/anonymous-proxy.html
US
shared
3128
μProxy Tool.exe
GET
101.255.79.18:44550
http://azenv.net/
ID
suspicious
3128
μProxy Tool.exe
GET
101.4.132.20:80
http://azenv.net/
CN
suspicious
3128
μProxy Tool.exe
GET
1.9.167.35:60489
http://azenv.net/
MY
suspicious
3128
μProxy Tool.exe
GET
1.161.153.239:1080
http://azenv.net/
TW
unknown
3128
μProxy Tool.exe
GET
301
134.119.217.244:80
http://spys.ru/free-proxy-list/RU/
FR
html
243 b
malicious
3128
μProxy Tool.exe
GET
200
104.28.7.171:80
http://www.thebigproxylist.com/
US
html
15.0 Kb
malicious
3128
μProxy Tool.exe
GET
200
134.119.217.244:80
http://spys.one/free-proxy-list/RU/
FR
html
6.33 Kb
malicious
3128
μProxy Tool.exe
GET
200
172.217.18.19:80
http://www.live-socks.net/feeds/posts/default
US
xml
3.68 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3128
μProxy Tool.exe
104.28.31.59:443
www.sslproxies.org
Cloudflare Inc
US
shared
3128
μProxy Tool.exe
23.254.165.218:80
rootjazz.com
Hostwinds LLC.
US
malicious
3128
μProxy Tool.exe
104.27.146.242:80
free-proxy-list.net
Cloudflare Inc
US
shared
3128
μProxy Tool.exe
91.186.19.233:443
premproxy.com
Simply Transit Ltd
GB
unknown
3128
μProxy Tool.exe
159.69.83.207:80
txt.proxyspy.net
US
malicious
3128
μProxy Tool.exe
173.249.19.172:80
proxyape.com
Contabo GmbH
US
unknown
3128
μProxy Tool.exe
104.28.7.171:80
www.thebigproxylist.com
Cloudflare Inc
US
shared
3128
μProxy Tool.exe
144.217.88.10:443
proxyunique.com
OVH SAS
CA
unknown
3128
μProxy Tool.exe
1.35.178.239:1080
Data Communication Business Group
TW
unknown
3128
μProxy Tool.exe
101.255.79.18:44550
PT Remala Abadi
ID
suspicious

DNS requests

Domain
IP
Reputation
premproxy.com
  • 91.186.19.233
unknown
aytacproxy.cf
malicious
www.proxydocker.com
  • 164.132.235.17
unknown
www.proxyserverlist24.top
  • 172.217.18.19
whitelisted
www.sslproxies.org
  • 104.28.31.59
  • 104.28.30.59
malicious
www.thebigproxylist.com
  • 104.28.7.171
  • 104.28.6.171
malicious
www.live-socks.net
  • 172.217.18.19
whitelisted
free-proxy-list.net
  • 104.27.146.242
  • 104.27.147.242
unknown
proxyunique.com
  • 144.217.88.10
suspicious
txt.proxyspy.net
  • 159.69.83.207
  • 159.69.42.212
  • 95.216.161.60
malicious

Threats

PID
Process
Class
Message
1056
svchost.exe
Potentially Bad Traffic
ET INFO DNS Query for Suspicious .cf Domain
1056
svchost.exe
Potentially Bad Traffic
ET DNS Query to a *.top domain - Likely Hostile
3128
μProxy Tool.exe
Potentially Bad Traffic
ET INFO HTTP Request to a *.top domain
No debug info