File name:

MYRZ Anti-Public Checker v0.87.7z

Full analysis: https://app.any.run/tasks/dd959181-669a-4109-a755-afb0d373994d
Verdict: Malicious activity
Analysis date: February 10, 2022, 05:58:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

E1D54DFE707215E309F52F171B62A171

SHA1:

0032CEF6DD45F92385107BDC8E921C40DB275336

SHA256:

823CD3D6DA5CAAF366801F15E6668C3E8EEB7AA716E72703EFD59AEAC85481B9

SSDEEP:

12288:AeKvC0ouZzwB3NTEYqncTbtE0fcTq2EiNvKOAbbu3M5AGBN3IJsmMjkN:A+GENJqGtNfcZEirqic/0Jja6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3604)
      • AntiPublic Updater.exe (PID: 3236)
      • AntiPublic.exe (PID: 2968)
      • AntiPublic Updater.exe (PID: 684)
      • Explorer.EXE (PID: 1108)
    • Application was dropped or rewritten from another process

      • AntiPublic Updater.exe (PID: 3236)
      • AntiPublic.exe (PID: 3952)
      • AntiPublic Updater.exe (PID: 684)
      • AntiPublic.exe (PID: 2968)
    • Changes settings of System certificates

      • AntiPublic.exe (PID: 2968)
  • SUSPICIOUS

    • Reads Environment values

      • AntiPublic.exe (PID: 3952)
      • AntiPublic Updater.exe (PID: 3236)
      • AntiPublic.exe (PID: 2968)
      • AntiPublic Updater.exe (PID: 684)
    • Reads the computer name

      • WinRAR.exe (PID: 1048)
      • AntiPublic.exe (PID: 3952)
      • AntiPublic Updater.exe (PID: 3236)
      • AntiPublic.exe (PID: 2968)
      • AntiPublic Updater.exe (PID: 684)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 1048)
    • Checks supported languages

      • WinRAR.exe (PID: 1048)
      • AntiPublic.exe (PID: 3952)
      • AntiPublic Updater.exe (PID: 3236)
      • AntiPublic Updater.exe (PID: 684)
      • AntiPublic.exe (PID: 2968)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 1048)
    • Reads default file associations for system extensions

      • Explorer.EXE (PID: 1108)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1048)
    • Adds / modifies Windows certificates

      • AntiPublic.exe (PID: 2968)
    • Starts Internet Explorer

      • AntiPublic.exe (PID: 2968)
    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 2792)
  • INFO

    • Manual execution by user

      • AntiPublic.exe (PID: 3952)
    • Reads settings of System Certificates

      • AntiPublic Updater.exe (PID: 3236)
      • AntiPublic.exe (PID: 2968)
      • AntiPublic Updater.exe (PID: 684)
    • Reads the computer name

      • iexplore.exe (PID: 4004)
      • iexplore.exe (PID: 2792)
    • Checks Windows Trust Settings

      • AntiPublic.exe (PID: 2968)
    • Checks supported languages

      • iexplore.exe (PID: 4004)
      • iexplore.exe (PID: 2792)
    • Changes internet zones settings

      • iexplore.exe (PID: 4004)
    • Application launched itself

      • iexplore.exe (PID: 4004)
    • Creates files in the user directory

      • iexplore.exe (PID: 2792)
    • Reads the date of Windows installation

      • iexplore.exe (PID: 4004)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
9
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs antipublic.exe explorer.exe no specs antipublic updater.exe antipublic.exe antipublic updater.exe iexplore.exe no specs iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
684"C:\Users\admin\Desktop\MYRZ Anti-Public Checker v0.87\AntiPublic Updater.exe" C:\Users\admin\Desktop\MYRZ Anti-Public Checker v0.87\AntiPublic Updater.exe
AntiPublic.exe
User:
admin
Company:
Newtonsoft
Integrity Level:
HIGH
Description:
Json.NET
Exit code:
0
Version:
9.0.1.19813
Modules
Images
c:\users\admin\desktop\myrz anti-public checker v0.87\antipublic updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1048"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\MYRZ Anti-Public Checker v0.87.7z"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1108C:\Windows\Explorer.EXEC:\Windows\Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2792"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:4004 CREDAT:275457 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2968"C:\Users\admin\Desktop\MYRZ Anti-Public Checker v0.87\AntiPublic.exe" C:\Users\admin\Desktop\MYRZ Anti-Public Checker v0.87\AntiPublic.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Description:
Exit code:
0
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\myrz anti-public checker v0.87\antipublic.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3236"C:\Users\admin\Desktop\MYRZ Anti-Public Checker v0.87\AntiPublic Updater.exe" C:\Users\admin\Desktop\MYRZ Anti-Public Checker v0.87\AntiPublic Updater.exe
Explorer.EXE
User:
admin
Company:
Newtonsoft
Integrity Level:
MEDIUM
Description:
Json.NET
Exit code:
0
Version:
9.0.1.19813
Modules
Images
c:\users\admin\desktop\myrz anti-public checker v0.87\antipublic updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
3604"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3952"C:\Users\admin\Desktop\MYRZ Anti-Public Checker v0.87\AntiPublic.exe" C:\Users\admin\Desktop\MYRZ Anti-Public Checker v0.87\AntiPublic.exe
Explorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Exit code:
4294967295
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\myrz anti-public checker v0.87\antipublic.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
4004"C:\Program Files\Internet Explorer\iexplore.exe" http://bit.ly/antipublic-buyC:\Program Files\Internet Explorer\iexplore.exeAntiPublic.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
Total events
17 454
Read events
17 166
Write events
287
Delete events
1

Modification events

(PID) Process:(1048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1048) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\MYRZ Anti-Public Checker v0.87.7z
(PID) Process:(1048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
9
Suspicious files
7
Text files
6
Unknown types
8

Dropped files

PID
Process
Filename
Type
1048WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1048.38131\MYRZ Anti-Public Checker v0.87\ru-RU\AntiPublic.resources.dllexecutable
MD5:
SHA256:
1048WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1048.38131\MYRZ Anti-Public Checker v0.87\en\AntiPublic.resources.dllexecutable
MD5:
SHA256:
1048WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1048.38131\MYRZ Anti-Public Checker v0.87\AntiPublic.exeexecutable
MD5:
SHA256:
2968AntiPublic.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:
SHA256:
1048WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1048.38131\MYRZ Anti-Public Checker v0.87\Newtonsoft.Json.dllexecutable
MD5:5AFDA7C7D4F7085E744C2E7599279DB3
SHA256:F58C374FFCAAE4E36D740D90FBF7FE70D0ABB7328CD9AF3A0A7B70803E994BA4
2968AntiPublic.exeC:\Users\admin\AppData\Local\IsolatedStorage\ezjt0og3.ifv\ijxyz321.lco\Url.lff1sgdyij0q4glbambllooxa2tarkd1\identity.datpi2
MD5:
SHA256:
2968AntiPublic.exeC:\Users\admin\AppData\Local\Temp\TarE423.tmpcat
MD5:D99661D0893A52A0700B8AE68457351A
SHA256:BDD5111162A6FA25682E18FA74E37E676D49CAFCB5B7207E98E5256D1EF0D003
2968AntiPublic.exeC:\Users\admin\AppData\Local\Temp\CabE422.tmpcompressed
MD5:ACAEDA60C79C6BCAC925EEB3653F45E0
SHA256:6B0CECCF0103AFD89844761417C1D23ACC41F8AEBF3B7230765209B61EEE5658
2968AntiPublic.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:ACAEDA60C79C6BCAC925EEB3653F45E0
SHA256:6B0CECCF0103AFD89844761417C1D23ACC41F8AEBF3B7230765209B61EEE5658
1048WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1048.38131\MYRZ Anti-Public Checker v0.87\GemBox.Email.dllexecutable
MD5:3657F2F4783FC9D9505B8C137AABA060
SHA256:A5899F6D6C6F3944DEC97CA32B4A915606EE7154ABCEC29020AF3C21AE9B3274
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
12
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2792
iexplore.exe
GET
301
67.199.248.11:80
http://bit.ly/antipublic-buy
US
html
140 b
shared
3952
AntiPublic.exe
GET
301
178.32.52.69:80
http://myrz.org/api/check_updates.php?do=version
GB
html
162 b
whitelisted
2968
AntiPublic.exe
GET
301
178.32.52.69:80
http://myrz.org/api/check.php?key=6eee9c57c0ad7f1caf2e2ffe6f4c2003&plus=1
GB
html
162 b
whitelisted
684
AntiPublic Updater.exe
GET
301
178.32.52.69:80
http://myrz.org/check_updates.php
GB
html
162 b
whitelisted
2968
AntiPublic.exe
GET
301
178.32.52.69:80
http://myrz.org/api/check_updates.php?do=version
GB
html
162 b
whitelisted
2968
AntiPublic.exe
GET
301
178.32.52.69:80
http://myrz.org/api/check.php?key=6eee9c57c0ad7f1caf2e2ffe6f4c2003&plus=1
GB
html
162 b
whitelisted
3236
AntiPublic Updater.exe
GET
301
178.32.52.69:80
http://myrz.org/check_updates.php
GB
html
162 b
whitelisted
2968
AntiPublic.exe
GET
200
67.26.137.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?294ad189d1e7b32a
US
compressed
59.9 Kb
whitelisted
2968
AntiPublic.exe
GET
301
178.32.52.69:80
http://myrz.org/api/check.php?key=6eee9c57c0ad7f1caf2e2ffe6f4c2003&plus=1
GB
html
162 b
whitelisted
2968
AntiPublic.exe
GET
301
178.32.52.69:80
http://myrz.org/api/check.php?key=6eee9c57c0ad7f1caf2e2ffe6f4c2003&plus=1
GB
html
162 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3952
AntiPublic.exe
178.32.52.69:80
myrz.org
OVH SAS
GB
suspicious
3952
AntiPublic.exe
178.32.52.69:443
myrz.org
OVH SAS
GB
suspicious
3236
AntiPublic Updater.exe
178.32.52.69:80
myrz.org
OVH SAS
GB
suspicious
2968
AntiPublic.exe
178.32.52.69:80
myrz.org
OVH SAS
GB
suspicious
684
AntiPublic Updater.exe
178.32.52.69:80
myrz.org
OVH SAS
GB
suspicious
2792
iexplore.exe
67.199.248.11:80
bit.ly
Bitly Inc
US
shared
3236
AntiPublic Updater.exe
178.32.52.69:443
myrz.org
OVH SAS
GB
suspicious
2968
AntiPublic.exe
178.32.52.69:443
myrz.org
OVH SAS
GB
suspicious
3236
AntiPublic Updater.exe
67.26.137.254:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
malicious
2968
AntiPublic.exe
67.26.137.254:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
malicious

DNS requests

Domain
IP
Reputation
myrz.org
  • 178.32.52.69
whitelisted
ctldl.windowsupdate.com
  • 67.26.137.254
  • 67.26.81.254
  • 8.253.95.120
  • 67.27.157.254
  • 67.26.139.254
whitelisted
bit.ly
  • 67.199.248.11
  • 67.199.248.10
shared
lolzteam.online
unknown

Threats

No threats detected
No debug info