File name:

MYRZ Anti-Public Checker v0.87.7z

Full analysis: https://app.any.run/tasks/dd959181-669a-4109-a755-afb0d373994d
Verdict: Malicious activity
Analysis date: February 10, 2022, 05:58:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

E1D54DFE707215E309F52F171B62A171

SHA1:

0032CEF6DD45F92385107BDC8E921C40DB275336

SHA256:

823CD3D6DA5CAAF366801F15E6668C3E8EEB7AA716E72703EFD59AEAC85481B9

SSDEEP:

12288:AeKvC0ouZzwB3NTEYqncTbtE0fcTq2EiNvKOAbbu3M5AGBN3IJsmMjkN:A+GENJqGtNfcZEirqic/0Jja6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3604)
      • Explorer.EXE (PID: 1108)
      • AntiPublic Updater.exe (PID: 3236)
      • AntiPublic.exe (PID: 2968)
      • AntiPublic Updater.exe (PID: 684)
    • Application was dropped or rewritten from another process

      • AntiPublic.exe (PID: 3952)
      • AntiPublic Updater.exe (PID: 3236)
      • AntiPublic.exe (PID: 2968)
      • AntiPublic Updater.exe (PID: 684)
    • Changes settings of System certificates

      • AntiPublic.exe (PID: 2968)
  • SUSPICIOUS

    • Checks supported languages

      • WinRAR.exe (PID: 1048)
      • AntiPublic.exe (PID: 3952)
      • AntiPublic Updater.exe (PID: 3236)
      • AntiPublic.exe (PID: 2968)
      • AntiPublic Updater.exe (PID: 684)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 1048)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 1048)
    • Reads the computer name

      • WinRAR.exe (PID: 1048)
      • AntiPublic.exe (PID: 3952)
      • AntiPublic Updater.exe (PID: 3236)
      • AntiPublic.exe (PID: 2968)
      • AntiPublic Updater.exe (PID: 684)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1048)
    • Reads default file associations for system extensions

      • Explorer.EXE (PID: 1108)
    • Reads Environment values

      • AntiPublic Updater.exe (PID: 3236)
      • AntiPublic.exe (PID: 3952)
      • AntiPublic.exe (PID: 2968)
      • AntiPublic Updater.exe (PID: 684)
    • Adds / modifies Windows certificates

      • AntiPublic.exe (PID: 2968)
    • Starts Internet Explorer

      • AntiPublic.exe (PID: 2968)
    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 2792)
  • INFO

    • Manual execution by user

      • AntiPublic.exe (PID: 3952)
    • Reads settings of System Certificates

      • AntiPublic Updater.exe (PID: 3236)
      • AntiPublic.exe (PID: 2968)
      • AntiPublic Updater.exe (PID: 684)
    • Application launched itself

      • iexplore.exe (PID: 4004)
    • Checks Windows Trust Settings

      • AntiPublic.exe (PID: 2968)
    • Checks supported languages

      • iexplore.exe (PID: 2792)
      • iexplore.exe (PID: 4004)
    • Reads the computer name

      • iexplore.exe (PID: 4004)
      • iexplore.exe (PID: 2792)
    • Changes internet zones settings

      • iexplore.exe (PID: 4004)
    • Creates files in the user directory

      • iexplore.exe (PID: 2792)
    • Reads the date of Windows installation

      • iexplore.exe (PID: 4004)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
9
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs antipublic.exe explorer.exe no specs antipublic updater.exe antipublic.exe antipublic updater.exe iexplore.exe no specs iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
684"C:\Users\admin\Desktop\MYRZ Anti-Public Checker v0.87\AntiPublic Updater.exe" C:\Users\admin\Desktop\MYRZ Anti-Public Checker v0.87\AntiPublic Updater.exe
AntiPublic.exe
User:
admin
Company:
Newtonsoft
Integrity Level:
HIGH
Description:
Json.NET
Exit code:
0
Version:
9.0.1.19813
Modules
Images
c:\users\admin\desktop\myrz anti-public checker v0.87\antipublic updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1048"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\MYRZ Anti-Public Checker v0.87.7z"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1108C:\Windows\Explorer.EXEC:\Windows\Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2792"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:4004 CREDAT:275457 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2968"C:\Users\admin\Desktop\MYRZ Anti-Public Checker v0.87\AntiPublic.exe" C:\Users\admin\Desktop\MYRZ Anti-Public Checker v0.87\AntiPublic.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Description:
Exit code:
0
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\myrz anti-public checker v0.87\antipublic.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3236"C:\Users\admin\Desktop\MYRZ Anti-Public Checker v0.87\AntiPublic Updater.exe" C:\Users\admin\Desktop\MYRZ Anti-Public Checker v0.87\AntiPublic Updater.exe
Explorer.EXE
User:
admin
Company:
Newtonsoft
Integrity Level:
MEDIUM
Description:
Json.NET
Exit code:
0
Version:
9.0.1.19813
Modules
Images
c:\users\admin\desktop\myrz anti-public checker v0.87\antipublic updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
3604"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3952"C:\Users\admin\Desktop\MYRZ Anti-Public Checker v0.87\AntiPublic.exe" C:\Users\admin\Desktop\MYRZ Anti-Public Checker v0.87\AntiPublic.exe
Explorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Exit code:
4294967295
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\myrz anti-public checker v0.87\antipublic.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
4004"C:\Program Files\Internet Explorer\iexplore.exe" http://bit.ly/antipublic-buyC:\Program Files\Internet Explorer\iexplore.exeAntiPublic.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
Total events
17 454
Read events
17 166
Write events
287
Delete events
1

Modification events

(PID) Process:(1048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1048) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\MYRZ Anti-Public Checker v0.87.7z
(PID) Process:(1048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
9
Suspicious files
7
Text files
6
Unknown types
8

Dropped files

PID
Process
Filename
Type
1048WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1048.38131\MYRZ Anti-Public Checker v0.87\ru-RU\AntiPublic.resources.dllexecutable
MD5:EE4F9DDA18E0A5E794108867866213DD
SHA256:AFEF162FC104EDB5068524AC9C63844547E82619AC9CA50D62712365AACDA59A
1048WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1048.38131\MYRZ Anti-Public Checker v0.87\AntiPublic.exeexecutable
MD5:0544236E3C67568604FB0296ED5820A4
SHA256:877D772D402CFB7B4F75E16F288774A653A5280B0CED4EEC11AABA4D66F6CC7C
1048WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1048.38131\MYRZ Anti-Public Checker v0.87\en\AntiPublic.resources.dllexecutable
MD5:35D4D6A1E6765B932C527006DF6149EA
SHA256:F2475DDCD003D5DD6403F0D85CB6FAD84CEB9308C8000876CB7E11BC7BA45AD0
2968AntiPublic.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:1F68738CE832512DF3EE23E8EC198FBD
SHA256:611EBB809ADECD32BD54D2D52032BCD25F5ADB6B78CA1CD25F07FA428394390E
1048WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1048.38131\MYRZ Anti-Public Checker v0.87\AntiPublic.exe.configxml
MD5:7FF9B53BDA5F73278906810DBA16FBB8
SHA256:40DD882945F96494FBAA9452085C0244A22C68CFA95CE514051FC276999F994C
2968AntiPublic.exeC:\Users\admin\AppData\Local\IsolatedStorage\ezjt0og3.ifv\ijxyz321.lco\Url.lff1sgdyij0q4glbambllooxa2tarkd1\identity.datpi2
MD5:E9444B9A8B669A8F0330053396D4DCC9
SHA256:E7BF5C3D7CCF00DA6C1A82BC9C9EDA44F818239100206767C91477002E19ED20
2968AntiPublic.exeC:\Users\admin\AppData\Local\IsolatedStorage\ezjt0og3.ifv\ijxyz321.lco\Url.lff1sgdyij0q4glbambllooxa2tarkd1\Publisher.qolcwimjscmc2r1axln3vci10dth4a4y\identity.datpi2
MD5:58E932654C06E907450C7FFF5D235E87
SHA256:2227DD3A72F2A0503F5EDF5B012F3B8B634B162D072B0CC2DC08379955F558C4
2968AntiPublic.exeC:\Users\admin\AppData\Local\Temp\CabE422.tmpcompressed
MD5:ACAEDA60C79C6BCAC925EEB3653F45E0
SHA256:6B0CECCF0103AFD89844761417C1D23ACC41F8AEBF3B7230765209B61EEE5658
1048WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1048.38131\MYRZ Anti-Public Checker v0.87\GemBox.Email.xmlxml
MD5:8655FDE8790C59D030ADEB2785272E11
SHA256:50E6A3EFB27C484E370F35BDD1441520AE9C5642277E0B62CB3B42AE7D6A1146
1048WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1048.38131\MYRZ Anti-Public Checker v0.87\ConsoleRegChecker.exeexecutable
MD5:E45AB7767CD2C15503F510F45150D6C4
SHA256:5CD12B3E976FCE79A0F19B30827F9FC07B209DECC557B65F41F296EBC6F8FABC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
12
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3952
AntiPublic.exe
GET
301
178.32.52.69:80
http://myrz.org/api/check_updates.php?do=version
GB
html
162 b
whitelisted
2968
AntiPublic.exe
GET
301
178.32.52.69:80
http://myrz.org/api/check_updates.php?do=version
GB
html
162 b
whitelisted
3236
AntiPublic Updater.exe
GET
301
178.32.52.69:80
http://myrz.org/check_updates.php
GB
html
162 b
whitelisted
2968
AntiPublic.exe
GET
301
178.32.52.69:80
http://myrz.org/api/check.php?key=6eee9c57c0ad7f1caf2e2ffe6f4c2003&plus=1
GB
html
162 b
whitelisted
2968
AntiPublic.exe
GET
200
67.26.137.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?294ad189d1e7b32a
US
compressed
59.9 Kb
whitelisted
684
AntiPublic Updater.exe
GET
301
178.32.52.69:80
http://myrz.org/check_updates.php
GB
html
162 b
whitelisted
2968
AntiPublic.exe
GET
301
178.32.52.69:80
http://myrz.org/api/check.php?key=6eee9c57c0ad7f1caf2e2ffe6f4c2003&plus=1
GB
html
162 b
whitelisted
2968
AntiPublic.exe
GET
301
178.32.52.69:80
http://myrz.org/api/check.php?key=6eee9c57c0ad7f1caf2e2ffe6f4c2003&plus=1
GB
html
162 b
whitelisted
2968
AntiPublic.exe
GET
301
178.32.52.69:80
http://myrz.org/api/check.php?key=6eee9c57c0ad7f1caf2e2ffe6f4c2003&plus=1
GB
html
162 b
whitelisted
2792
iexplore.exe
GET
301
67.199.248.11:80
http://bit.ly/antipublic-buy
US
html
140 b
shared
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2968
AntiPublic.exe
67.26.137.254:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
malicious
684
AntiPublic Updater.exe
178.32.52.69:80
myrz.org
OVH SAS
GB
suspicious
3952
AntiPublic.exe
178.32.52.69:80
myrz.org
OVH SAS
GB
suspicious
3952
AntiPublic.exe
178.32.52.69:443
myrz.org
OVH SAS
GB
suspicious
3236
AntiPublic Updater.exe
178.32.52.69:80
myrz.org
OVH SAS
GB
suspicious
3236
AntiPublic Updater.exe
178.32.52.69:443
myrz.org
OVH SAS
GB
suspicious
684
AntiPublic Updater.exe
178.32.52.69:443
myrz.org
OVH SAS
GB
suspicious
2792
iexplore.exe
67.199.248.11:80
bit.ly
Bitly Inc
US
shared
3236
AntiPublic Updater.exe
67.26.137.254:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
malicious
2968
AntiPublic.exe
178.32.52.69:80
myrz.org
OVH SAS
GB
suspicious

DNS requests

Domain
IP
Reputation
myrz.org
  • 178.32.52.69
whitelisted
ctldl.windowsupdate.com
  • 67.26.137.254
  • 67.26.81.254
  • 8.253.95.120
  • 67.27.157.254
  • 67.26.139.254
whitelisted
bit.ly
  • 67.199.248.11
  • 67.199.248.10
shared
lolzteam.online
unknown

Threats

No threats detected
No debug info