File name:

TaskbarX_1.6.1.0.zip

Full analysis: https://app.any.run/tasks/210539e1-93db-4049-98de-1ca622c8ac64
Verdict: Malicious activity
Analysis date: September 28, 2020, 23:58:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

786B6B994B1FDD74780BE1A60BBC8226

SHA1:

004DB675301CF3133C7CCD24793E21BD5F5A7C3F

SHA256:

750E4D2B1008AABE005BC877A284145D84567A3A0D490465E41FEAA073FAC2C0

SSDEEP:

49152:3nhFc9i5w/gV38ufThiMb51kVOSgCai0UlAwhtwqd0sQ6pLDer:3nfc9sw/giIhpt1Ma9wh50sQ6pL0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 1956)
      • TaskbarX Configurator.exe (PID: 3884)
    • Application was dropped or rewritten from another process

      • TaskbarX.exe (PID: 3284)
      • TaskbarX Configurator.exe (PID: 3884)
      • TaskbarX.exe (PID: 2032)
      • TaskbarX.exe (PID: 1484)
      • TaskbarX.exe (PID: 1500)
      • TaskbarX.exe (PID: 3508)
      • TaskbarX.exe (PID: 3184)
      • TaskbarX.exe (PID: 1712)
      • TaskbarX.exe (PID: 2380)
    • Loads the Task Scheduler COM API

      • TaskbarX Configurator.exe (PID: 3884)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3848)
    • Reads Environment values

      • TaskbarX Configurator.exe (PID: 3884)
  • INFO

    • Manual execution by user

      • TaskbarX.exe (PID: 3284)
      • TaskbarX Configurator.exe (PID: 3884)
      • TaskbarX.exe (PID: 1712)
    • Reads settings of System Certificates

      • TaskbarX Configurator.exe (PID: 3884)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2019:08:27 11:00:05
ZipCRC: 0x537d7737
ZipCompressedSize: 61829
ZipUncompressedSize: 441344
ZipFileName: Emoji.Wpf.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
11
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs taskbarx.exe no specs taskbarx configurator.exe taskbarx.exe no specs taskbarx.exe no specs taskbarx.exe no specs taskbarx.exe no specs taskbarx.exe no specs taskbarx.exe no specs taskbarx.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1484"C:\Users\admin\Desktop\TaskbarX.exe" -tbs=1 -color=0;0;0;50 -as=cubiceaseinout -obas=cubiceaseinout -asp=300 -ptbo=0 -stbo=0 -lr=400 -oblr=400 -sr=0 -ftotc=1 C:\Users\admin\Desktop\TaskbarX.exeTaskbarX Configurator.exe
User:
admin
Company:
Chris Andriessen
Integrity Level:
MEDIUM
Description:
TaskbarX
Exit code:
0
Version:
1.6.1.0
Modules
Images
c:\users\admin\desktop\taskbarx.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1500"C:\Users\admin\Desktop\TaskbarX.exe" -stopC:\Users\admin\Desktop\TaskbarX.exeTaskbarX Configurator.exe
User:
admin
Company:
Chris Andriessen
Integrity Level:
MEDIUM
Description:
TaskbarX
Exit code:
0
Version:
1.6.1.0
Modules
Images
c:\users\admin\desktop\taskbarx.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1712"C:\Users\admin\Desktop\TaskbarX.exe" C:\Users\admin\Desktop\TaskbarX.exeexplorer.exe
User:
admin
Company:
Chris Andriessen
Integrity Level:
MEDIUM
Description:
TaskbarX
Exit code:
0
Version:
1.6.1.0
Modules
Images
c:\users\admin\desktop\taskbarx.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1956"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2032"C:\Users\admin\Desktop\TaskbarX.exe" -stopC:\Users\admin\Desktop\TaskbarX.exeTaskbarX Configurator.exe
User:
admin
Company:
Chris Andriessen
Integrity Level:
MEDIUM
Description:
TaskbarX
Exit code:
0
Version:
1.6.1.0
Modules
Images
c:\users\admin\desktop\taskbarx.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2380"C:\Users\admin\Desktop\TaskbarX.exe" -stopC:\Users\admin\Desktop\TaskbarX.exeTaskbarX Configurator.exe
User:
admin
Company:
Chris Andriessen
Integrity Level:
MEDIUM
Description:
TaskbarX
Exit code:
0
Version:
1.6.1.0
Modules
Images
c:\users\admin\desktop\taskbarx.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3184"C:\Users\admin\Desktop\TaskbarX.exe" -tbs=1 -color=0;0;0;50 -as=cubiceaseinout -obas=cubiceaseinout -asp=300 -ptbo=0 -stbo=0 -lr=400 -oblr=400 -sr=0 -ftotc=1 C:\Users\admin\Desktop\TaskbarX.exeTaskbarX Configurator.exe
User:
admin
Company:
Chris Andriessen
Integrity Level:
MEDIUM
Description:
TaskbarX
Exit code:
0
Version:
1.6.1.0
Modules
Images
c:\users\admin\desktop\taskbarx.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3284"C:\Users\admin\Desktop\TaskbarX.exe" C:\Users\admin\Desktop\TaskbarX.exeexplorer.exe
User:
admin
Company:
Chris Andriessen
Integrity Level:
MEDIUM
Description:
TaskbarX
Exit code:
0
Version:
1.6.1.0
Modules
Images
c:\users\admin\desktop\taskbarx.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3508"C:\Users\admin\Desktop\TaskbarX.exe" -tbs=1 -color=0;0;0;50 -as=cubiceaseinout -obas=cubiceaseinout -asp=300 -ptbo=0 -stbo=0 -lr=400 -oblr=400 -sr=0 -ftotc=1 C:\Users\admin\Desktop\TaskbarX.exeTaskbarX Configurator.exe
User:
admin
Company:
Chris Andriessen
Integrity Level:
MEDIUM
Description:
TaskbarX
Exit code:
4294967295
Version:
1.6.1.0
Modules
Images
c:\users\admin\desktop\taskbarx.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3848"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\TaskbarX_1.6.1.0.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
599
Read events
542
Write events
57
Delete events
0

Modification events

(PID) Process:(3848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3848) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\TaskbarX_1.6.1.0.zip
(PID) Process:(3848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3848) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:@C:\Windows\System32\msxml3r.dll,-1
Value:
XML Document
(PID) Process:(3848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
Executable files
13
Suspicious files
0
Text files
8
Unknown types
2

Dropped files

PID
Process
Filename
Type
3848WinRAR.exeC:\Users\admin\Desktop\ModernWpf.Controls.dllexecutable
MD5:
SHA256:
3848WinRAR.exeC:\Users\admin\Desktop\ModernWpf.dllexecutable
MD5:
SHA256:
3848WinRAR.exeC:\Users\admin\Desktop\ModernWpf.xmlxml
MD5:
SHA256:
3848WinRAR.exeC:\Users\admin\Desktop\Emoji.Wpf.dllexecutable
MD5:
SHA256:
3848WinRAR.exeC:\Users\admin\Desktop\Microsoft.Win32.TaskScheduler.xmlxml
MD5:
SHA256:
3848WinRAR.exeC:\Users\admin\Desktop\Microsoft.Win32.TaskScheduler.dllexecutable
MD5:A0E1990702ADF1E28D7E447F58A0AA18
SHA256:510E386DF4CA1D9EA8FB0CFA365ED4C30FD22C422CA8F3F829E14A825A3D437F
3848WinRAR.exeC:\Users\admin\Desktop\ModernWpf.Controls.xmlxml
MD5:C1AE93D5031E87157FA52438CC37DD99
SHA256:C78D9783B0760E02B6A0BA7CEDC2F02527D6A77E16FED47E3EB4C92E4CBF17CE
3848WinRAR.exeC:\Users\admin\Desktop\System.dllexecutable
MD5:06775A34E91192599E60CCC403B60304
SHA256:18108BFCDCECA8FAE6A5E83848250F3D592115E8332CC7D13F97CBB800A151E4
3848WinRAR.exeC:\Users\admin\Desktop\TaskbarX Configurator.exeexecutable
MD5:
SHA256:
3848WinRAR.exeC:\Users\admin\Desktop\TaskbarX Configurator.pdbpdb
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3884
TaskbarX Configurator.exe
151.101.0.133:443
raw.githubusercontent.com
Fastly
US
malicious

DNS requests

Domain
IP
Reputation
raw.githubusercontent.com
  • 151.101.0.133
  • 151.101.64.133
  • 151.101.128.133
  • 151.101.192.133
shared

Threats

No threats detected
No debug info