File name:

13765233eb136ec97b453d3e631e8662741d66662bb3980eff5a2f9ced84a214.bin.gz

Full analysis: https://app.any.run/tasks/ffd78911-f8dd-46cf-8f29-7d7ead93788b
Verdict: Malicious activity
Threats:

Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email.

Analysis date: August 23, 2020, 17:04:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
Indicators:
MIME: application/gzip
File info: gzip compressed data, max speed, from Unix
MD5:

96E012DFA03708C4FED9DCFCECA755A3

SHA1:

1FCAC31F38E32F108F9881E6C6D13A08642DDC6C

SHA256:

826A9E0796D75316F5B4EC073B740897C74E419D1992FA4E3429A9906D73FD26

SSDEEP:

24576:pBM4LWD/BGMFjz0DwHD2/4lMNskYMg6mi5B/sX:pC4s/px3DblmP5g6f59+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • 13765233eb136ec97b453d3e631e8662741d66662bb3980eff5a2f9ced84a214.bin.exe (PID: 3540)
      • 13765233eb136ec97b453d3e631e8662741d66662bb3980eff5a2f9ced84a214.bin.exe (PID: 1924)
      • FlexGridService.exe (PID: 2984)
    • Connects to CnC server

      • FlexGridService.exe (PID: 2984)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 13765233eb136ec97b453d3e631e8662741d66662bb3980eff5a2f9ced84a214.bin.exe (PID: 3540)
    • Creates files in the program directory

      • 13765233eb136ec97b453d3e631e8662741d66662bb3980eff5a2f9ced84a214.bin.exe (PID: 3540)
      • FlexGridService.exe (PID: 2984)
      • 13765233eb136ec97b453d3e631e8662741d66662bb3980eff5a2f9ced84a214.bin.exe (PID: 1924)
    • Reads Internet Cache Settings

      • FlexGridService.exe (PID: 2984)
  • INFO

    • Manual execution by user

      • 13765233eb136ec97b453d3e631e8662741d66662bb3980eff5a2f9ced84a214.bin.exe (PID: 3540)
      • 13765233eb136ec97b453d3e631e8662741d66662bb3980eff5a2f9ced84a214.bin.exe (PID: 1924)
      • FlexGridService.exe (PID: 2984)
      • explorer.exe (PID: 444)
    • Reads the hosts file

      • FlexGridService.exe (PID: 2984)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.z/gz/gzip | GZipped data (100)

EXIF

ZIP

Compression: Deflated
Flags: (none)
ModifyDate: 0000:00:00 00:00:00
ExtraFlags: Fastest Algorithm
OperatingSystem: Unix
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs 13765233eb136ec97b453d3e631e8662741d66662bb3980eff5a2f9ced84a214.bin.exe 13765233eb136ec97b453d3e631e8662741d66662bb3980eff5a2f9ced84a214.bin.exe no specs explorer.exe no specs flexgridservice.exe

Process information

PID
CMD
Path
Indicators
Parent process
444"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
880"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\13765233eb136ec97b453d3e631e8662741d66662bb3980eff5a2f9ced84a214.bin.gz"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1924"C:\Users\admin\Desktop\13765233eb136ec97b453d3e631e8662741d66662bb3980eff5a2f9ced84a214.bin.exe" C:\Users\admin\Desktop\13765233eb136ec97b453d3e631e8662741d66662bb3980eff5a2f9ced84a214.bin.exeexplorer.exe
User:
admin
Company:
SBreeder
Integrity Level:
MEDIUM
Description:
2MIDI converter
Exit code:
0
Version:
5.4.0.11
Modules
Images
c:\users\admin\desktop\13765233eb136ec97b453d3e631e8662741d66662bb3980eff5a2f9ced84a214.bin.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winspool.drv
2984"C:\ProgramData\FlexGridService\FlexGridService.exe" C:\ProgramData\FlexGridService\FlexGridService.exe
explorer.exe
User:
admin
Company:
SBreeder
Integrity Level:
MEDIUM
Description:
2MIDI converter
Exit code:
0
Version:
5.4.0.11
Modules
Images
c:\programdata\flexgridservice\flexgridservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winspool.drv
3540"C:\Users\admin\Desktop\13765233eb136ec97b453d3e631e8662741d66662bb3980eff5a2f9ced84a214.bin.exe" C:\Users\admin\Desktop\13765233eb136ec97b453d3e631e8662741d66662bb3980eff5a2f9ced84a214.bin.exe
explorer.exe
User:
admin
Company:
SBreeder
Integrity Level:
MEDIUM
Description:
2MIDI converter
Exit code:
0
Version:
5.4.0.11
Modules
Images
c:\users\admin\desktop\13765233eb136ec97b453d3e631e8662741d66662bb3980eff5a2f9ced84a214.bin.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winspool.drv
Total events
491
Read events
462
Write events
29
Delete events
0

Modification events

(PID) Process:(880) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(880) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(880) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\136\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(880) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\136\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(880) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\13765233eb136ec97b453d3e631e8662741d66662bb3980eff5a2f9ced84a214.bin.gz
(PID) Process:(880) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(880) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(880) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(880) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(880) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
1
Suspicious files
1
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
880WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa880.10609\13765233eb136ec97b453d3e631e8662741d66662bb3980eff5a2f9ced84a214.bin
MD5:
SHA256:
2984FlexGridService.exeC:\ProgramData\ts.dattext
MD5:
SHA256:
2984FlexGridService.exeC:\ProgramData\irw.atsdtext
MD5:C2CB56F4C5BF656FACA0986E7EBA0308
SHA256:12A3AE445661CE5DEE78D0650D33362DEC29C4F82AF05E7E57FB595BBBACF0CA
354013765233eb136ec97b453d3e631e8662741d66662bb3980eff5a2f9ced84a214.bin.exeC:\ProgramData\FlexGridService\FlexGridService.exeexecutable
MD5:55A14F9E05962654F774B8129EC4C2CA
SHA256:13765233EB136EC97B453D3E631E8662741D66662BB3980EFF5A2F9CED84A214
192413765233eb136ec97b453d3e631e8662741d66662bb3980eff5a2f9ced84a214.bin.exeC:\ProgramData\irw.atsdtext
MD5:A54F0041A9E15B050F25C463F1DB7449
SHA256:AD95131BC0B799C0B1AF477FB14FCF26A6A9F76079E48BF090ACB7E8367BFD0E
2984FlexGridService.exeC:\ProgramData\rc.datbinary
MD5:4352D88A78AA39750BF70CD6F27BCAA5
SHA256:67ABDD721024F0FF4E0B3F4C2FC13BC5BAD42D0B7851D456D88D203D15AAA450
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
8
DNS requests
7
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2984
FlexGridService.exe
GET
185.141.63.172:80
http://eovzciq.ua/single.php?c=94bf3661c794e3eb1ba46c008930ec68d80a3eec48a792c6c460983d96735657a011e5d2855f6c1fae6fce89c643f3d6f2044c01951cf55ab1c84374385a198a9be40e89a986ada408f992eab41eaf9caf29618fd6d735fa4553
unknown
malicious
2984
FlexGridService.exe
GET
200
109.236.88.134:80
http://bddns.cc/sign/92bc297eca89cdac0af86e0edc63be6ed85f29
NL
text
28 b
suspicious
2984
FlexGridService.exe
GET
200
185.141.63.172:80
http://eovzciq.ua/single.php?c=94bf3661c794e3eb1ba46c008930ec68d80a3eec48a792c6c460983d96725657a011e5d2855f6c1fae6fce8bd311a185a1071450d55da71ab9d802362b5b018b84f55cdeec9df9e518b0cbf1e15fff99ac2c6a83d7d2
unknown
text
14 b
malicious
2984
FlexGridService.exe
GET
200
185.141.63.172:80
http://eovzciq.ua/single.php?c=94bf3661c794e3eb1ba46c008930ec68d80a3eec48a792c6c460983d96725657a011e5d2855f6c1fae6fce8bd311a185a1071450d55da71ab9d802362b5b018b84f55cdeec9df9e518b0cbf1e15fff99ac2c6a83d7d2
unknown
text
252 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2984
FlexGridService.exe
163.172.91.242:53
Online S.a.s.
FR
unknown
2984
FlexGridService.exe
217.23.6.51:53
WorldStream B.V.
NL
unknown
2984
FlexGridService.exe
151.80.38.159:53
OVH SAS
FR
unknown
2984
FlexGridService.exe
217.23.9.168:53
WorldStream B.V.
NL
unknown
2984
FlexGridService.exe
37.187.122.227:53
OVH SAS
FR
unknown
2984
FlexGridService.exe
109.236.88.134:80
bddns.cc
WorldStream B.V.
NL
suspicious
2984
FlexGridService.exe
185.141.63.172:80
malicious
2984
FlexGridService.exe
195.154.118.238:1074
Online S.a.s.
FR
unknown

DNS requests

Domain
IP
Reputation
eovzciq.ua
unknown
bddns.cc
  • 109.236.88.134
suspicious

Threats

PID
Process
Class
Message
1052
svchost.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
2984
FlexGridService.exe
A Network Trojan was detected
ET INFO Suspicious Windows NT version 9 User-Agent
2984
FlexGridService.exe
A Network Trojan was detected
ET INFO Suspicious Windows NT version 9 User-Agent
2984
FlexGridService.exe
A Network Trojan was detected
ET INFO Suspicious Windows NT version 9 User-Agent
2 ETPRO signatures available at the full report
No debug info