File name:

MYRZ Anti-Public Checker v0.87.7z

Full analysis: https://app.any.run/tasks/dd959181-669a-4109-a755-afb0d373994d
Verdict: Malicious activity
Analysis date: February 10, 2022, 05:58:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

E1D54DFE707215E309F52F171B62A171

SHA1:

0032CEF6DD45F92385107BDC8E921C40DB275336

SHA256:

823CD3D6DA5CAAF366801F15E6668C3E8EEB7AA716E72703EFD59AEAC85481B9

SSDEEP:

12288:AeKvC0ouZzwB3NTEYqncTbtE0fcTq2EiNvKOAbbu3M5AGBN3IJsmMjkN:A+GENJqGtNfcZEirqic/0Jja6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • AntiPublic.exe (PID: 3952)
      • AntiPublic Updater.exe (PID: 3236)
      • AntiPublic.exe (PID: 2968)
      • AntiPublic Updater.exe (PID: 684)
    • Loads dropped or rewritten executable

      • Explorer.EXE (PID: 1108)
      • SearchProtocolHost.exe (PID: 3604)
      • AntiPublic Updater.exe (PID: 3236)
      • AntiPublic Updater.exe (PID: 684)
      • AntiPublic.exe (PID: 2968)
    • Changes settings of System certificates

      • AntiPublic.exe (PID: 2968)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 1048)
      • AntiPublic.exe (PID: 3952)
      • AntiPublic Updater.exe (PID: 3236)
      • AntiPublic.exe (PID: 2968)
      • AntiPublic Updater.exe (PID: 684)
    • Checks supported languages

      • WinRAR.exe (PID: 1048)
      • AntiPublic.exe (PID: 3952)
      • AntiPublic Updater.exe (PID: 3236)
      • AntiPublic.exe (PID: 2968)
      • AntiPublic Updater.exe (PID: 684)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 1048)
    • Reads default file associations for system extensions

      • Explorer.EXE (PID: 1108)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1048)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 1048)
    • Reads Environment values

      • AntiPublic.exe (PID: 3952)
      • AntiPublic Updater.exe (PID: 3236)
      • AntiPublic.exe (PID: 2968)
      • AntiPublic Updater.exe (PID: 684)
    • Adds / modifies Windows certificates

      • AntiPublic.exe (PID: 2968)
    • Starts Internet Explorer

      • AntiPublic.exe (PID: 2968)
    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 2792)
  • INFO

    • Manual execution by user

      • AntiPublic.exe (PID: 3952)
    • Reads settings of System Certificates

      • AntiPublic Updater.exe (PID: 3236)
      • AntiPublic.exe (PID: 2968)
      • AntiPublic Updater.exe (PID: 684)
    • Checks Windows Trust Settings

      • AntiPublic.exe (PID: 2968)
    • Checks supported languages

      • iexplore.exe (PID: 4004)
      • iexplore.exe (PID: 2792)
    • Reads the computer name

      • iexplore.exe (PID: 4004)
      • iexplore.exe (PID: 2792)
    • Changes internet zones settings

      • iexplore.exe (PID: 4004)
    • Application launched itself

      • iexplore.exe (PID: 4004)
    • Creates files in the user directory

      • iexplore.exe (PID: 2792)
    • Reads the date of Windows installation

      • iexplore.exe (PID: 4004)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
9
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs antipublic.exe explorer.exe no specs antipublic updater.exe antipublic.exe antipublic updater.exe iexplore.exe no specs iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
684"C:\Users\admin\Desktop\MYRZ Anti-Public Checker v0.87\AntiPublic Updater.exe" C:\Users\admin\Desktop\MYRZ Anti-Public Checker v0.87\AntiPublic Updater.exe
AntiPublic.exe
User:
admin
Company:
Newtonsoft
Integrity Level:
HIGH
Description:
Json.NET
Exit code:
0
Version:
9.0.1.19813
Modules
Images
c:\users\admin\desktop\myrz anti-public checker v0.87\antipublic updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1048"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\MYRZ Anti-Public Checker v0.87.7z"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1108C:\Windows\Explorer.EXEC:\Windows\Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2792"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:4004 CREDAT:275457 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2968"C:\Users\admin\Desktop\MYRZ Anti-Public Checker v0.87\AntiPublic.exe" C:\Users\admin\Desktop\MYRZ Anti-Public Checker v0.87\AntiPublic.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Description:
Exit code:
0
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\myrz anti-public checker v0.87\antipublic.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3236"C:\Users\admin\Desktop\MYRZ Anti-Public Checker v0.87\AntiPublic Updater.exe" C:\Users\admin\Desktop\MYRZ Anti-Public Checker v0.87\AntiPublic Updater.exe
Explorer.EXE
User:
admin
Company:
Newtonsoft
Integrity Level:
MEDIUM
Description:
Json.NET
Exit code:
0
Version:
9.0.1.19813
Modules
Images
c:\users\admin\desktop\myrz anti-public checker v0.87\antipublic updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
3604"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3952"C:\Users\admin\Desktop\MYRZ Anti-Public Checker v0.87\AntiPublic.exe" C:\Users\admin\Desktop\MYRZ Anti-Public Checker v0.87\AntiPublic.exe
Explorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Exit code:
4294967295
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\myrz anti-public checker v0.87\antipublic.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
4004"C:\Program Files\Internet Explorer\iexplore.exe" http://bit.ly/antipublic-buyC:\Program Files\Internet Explorer\iexplore.exeAntiPublic.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
Total events
17 454
Read events
17 166
Write events
287
Delete events
1

Modification events

(PID) Process:(1048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1048) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\MYRZ Anti-Public Checker v0.87.7z
(PID) Process:(1048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
9
Suspicious files
7
Text files
6
Unknown types
8

Dropped files

PID
Process
Filename
Type
1048WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1048.38131\MYRZ Anti-Public Checker v0.87\AntiPublic.exeexecutable
MD5:
SHA256:
1048WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1048.38131\MYRZ Anti-Public Checker v0.87\en\AntiPublic.resources.dllexecutable
MD5:
SHA256:
1048WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1048.38131\MYRZ Anti-Public Checker v0.87\ru-RU\AntiPublic.resources.dllexecutable
MD5:
SHA256:
1048WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1048.38131\MYRZ Anti-Public Checker v0.87\AltoControls.dllexecutable
MD5:B581A0648CE87B6E293E45A87D02C4A1
SHA256:3252DC102E53EE98CEEE6B5945AD2A9A552831C581EEAD76BD22C30C5C2633D5
2968AntiPublic.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:
SHA256:
1048WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1048.38131\MYRZ Anti-Public Checker v0.87\GemBox.Email.dllexecutable
MD5:3657F2F4783FC9D9505B8C137AABA060
SHA256:A5899F6D6C6F3944DEC97CA32B4A915606EE7154ABCEC29020AF3C21AE9B3274
1048WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1048.38131\MYRZ Anti-Public Checker v0.87\ConsoleRegChecker.exeexecutable
MD5:E45AB7767CD2C15503F510F45150D6C4
SHA256:5CD12B3E976FCE79A0F19B30827F9FC07B209DECC557B65F41F296EBC6F8FABC
1048WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1048.38131\MYRZ Anti-Public Checker v0.87\GemBox.Email.xmlxml
MD5:8655FDE8790C59D030ADEB2785272E11
SHA256:50E6A3EFB27C484E370F35BDD1441520AE9C5642277E0B62CB3B42AE7D6A1146
1048WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1048.38131\MYRZ Anti-Public Checker v0.87\Newtonsoft.Json.dllexecutable
MD5:5AFDA7C7D4F7085E744C2E7599279DB3
SHA256:F58C374FFCAAE4E36D740D90FBF7FE70D0ABB7328CD9AF3A0A7B70803E994BA4
1048WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1048.38131\MYRZ Anti-Public Checker v0.87\Newtonsoft.Json.xmlxml
MD5:002B6E4720F86BFA2B6098522CFC7E6E
SHA256:C8CF955C563BDD25645D88130EAE335BC5EEA5E9D5AE71628FB46D7466204847
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
12
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2968
AntiPublic.exe
GET
301
178.32.52.69:80
http://myrz.org/api/check.php?key=6eee9c57c0ad7f1caf2e2ffe6f4c2003&plus=1
GB
html
162 b
whitelisted
2968
AntiPublic.exe
GET
301
178.32.52.69:80
http://myrz.org/api/check_updates.php?do=version
GB
html
162 b
whitelisted
3236
AntiPublic Updater.exe
GET
301
178.32.52.69:80
http://myrz.org/check_updates.php
GB
html
162 b
whitelisted
2968
AntiPublic.exe
GET
301
178.32.52.69:80
http://myrz.org/api/check.php?key=6eee9c57c0ad7f1caf2e2ffe6f4c2003&plus=1
GB
html
162 b
whitelisted
2968
AntiPublic.exe
GET
301
178.32.52.69:80
http://myrz.org/api/check.php?key=6eee9c57c0ad7f1caf2e2ffe6f4c2003&plus=1
GB
html
162 b
whitelisted
3952
AntiPublic.exe
GET
301
178.32.52.69:80
http://myrz.org/api/check_updates.php?do=version
GB
html
162 b
whitelisted
2968
AntiPublic.exe
GET
200
67.26.137.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?294ad189d1e7b32a
US
compressed
59.9 Kb
whitelisted
2968
AntiPublic.exe
GET
301
178.32.52.69:80
http://myrz.org/api/check.php?key=6eee9c57c0ad7f1caf2e2ffe6f4c2003&plus=1
GB
html
162 b
whitelisted
2792
iexplore.exe
GET
301
67.199.248.11:80
http://bit.ly/antipublic-buy
US
html
140 b
shared
2968
AntiPublic.exe
GET
301
178.32.52.69:80
http://myrz.org/api/check.php?key=6eee9c57c0ad7f1caf2e2ffe6f4c2003&plus=1
GB
html
162 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3236
AntiPublic Updater.exe
67.26.137.254:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
malicious
3236
AntiPublic Updater.exe
178.32.52.69:443
myrz.org
OVH SAS
GB
suspicious
684
AntiPublic Updater.exe
178.32.52.69:80
myrz.org
OVH SAS
GB
suspicious
2968
AntiPublic.exe
67.26.137.254:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
malicious
2968
AntiPublic.exe
178.32.52.69:80
myrz.org
OVH SAS
GB
suspicious
2968
AntiPublic.exe
178.32.52.69:443
myrz.org
OVH SAS
GB
suspicious
684
AntiPublic Updater.exe
178.32.52.69:443
myrz.org
OVH SAS
GB
suspicious
2792
iexplore.exe
67.199.248.11:80
bit.ly
Bitly Inc
US
shared
3952
AntiPublic.exe
178.32.52.69:80
myrz.org
OVH SAS
GB
suspicious
3952
AntiPublic.exe
178.32.52.69:443
myrz.org
OVH SAS
GB
suspicious

DNS requests

Domain
IP
Reputation
myrz.org
  • 178.32.52.69
whitelisted
ctldl.windowsupdate.com
  • 67.26.137.254
  • 67.26.81.254
  • 8.253.95.120
  • 67.27.157.254
  • 67.26.139.254
whitelisted
bit.ly
  • 67.199.248.11
  • 67.199.248.10
shared
lolzteam.online
unknown

Threats

No threats detected
No debug info