File name:

Proxy Gear Pro v2.1.rar

Full analysis: https://app.any.run/tasks/5a865b7f-1370-4a27-bd47-4b4ea6c7202e
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: August 02, 2018, 20:13:09
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
autoit
trojan
evasion
nanocore
rat
loader
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

C1D65BDA8631860DA7E2DF2BE31F0FC2

SHA1:

DFAC23B0BA522EDDA62ECE259DBBCD7972573835

SHA256:

86CD8B2ABD12A31CEF60DD0E4DBF49D4F6263B99CC50C8A648730C4211C69095

SSDEEP:

24576:6CmwcisMvlFNMdsR0QGVTp4TnCAA98Dh8hN1RM37bqb98Q3xlmdHMU7hR6PrTHVm:pmwcijF7CzALhkN1RM888mdd7hR6zM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Downloads executable files from the Internet

      • Proxy Gear Pro.exe (PID: 2876)
    • Changes the autorun value in the registry

      • RegAsm.exe (PID: 2612)
    • NanoCore was detected

      • RegAsm.exe (PID: 2612)
    • Application was dropped or rewritten from another process

      • pgpro.exe (PID: 3024)
      • RegAsm.exe (PID: 2612)
    • Connects to CnC server

      • RegAsm.exe (PID: 2612)
  • SUSPICIOUS

    • Creates files in the user directory

      • Proxy Gear Pro.exe (PID: 2876)
      • RegAsm.exe (PID: 2612)
    • Checks for external IP

      • pgpro.exe (PID: 3024)
    • Reads internet explorer settings

      • pgpro.exe (PID: 3024)
    • Executable content was dropped or overwritten

      • Proxy Gear Pro.exe (PID: 2876)
      • RegAsm.exe (PID: 2612)
    • Reads Internet Cache Settings

      • rundll32.exe (PID: 1044)
    • Connects to unusual port

      • RegAsm.exe (PID: 2612)
  • INFO

    • Dropped object may contain URL's

      • pgpro.exe (PID: 3024)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start winrar.exe no specs proxy gear pro.exe rundll32.exe no specs pgpro.exe THREAT regasm.exe

Process information

PID
CMD
Path
Indicators
Parent process
1044"C:\Windows\system32\rundll32.exe" "C:\Windows\system32\WININET.dll",DispatchAPICall 1 C:\Windows\system32\rundll32.exeProxy Gear Pro.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imagehlp.dll
2612"C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe"C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
Proxy Gear Pro.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Assembly Registration Utility
Exit code:
0
Version:
2.0.50727.5420 (Win7SP1.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\regasm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
2876"C:\Users\admin\Desktop\Proxy Gear Pro v2.1\Proxy Gear Pro.exe" C:\Users\admin\Desktop\Proxy Gear Pro v2.1\Proxy Gear Pro.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Proxy Gear Pro
Exit code:
0
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\proxy gear pro v2.1\proxy gear pro.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
3024"C:\Users\admin\AppData\Local\Temp\pgpro.exe" C:\Users\admin\AppData\Local\Temp\pgpro.exe
Proxy Gear Pro.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Proxy Gear Pro
Exit code:
0
Version:
2.1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\pgpro.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
3676"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Proxy Gear Pro v2.1.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
935
Read events
877
Write events
58
Delete events
0

Modification events

(PID) Process:(3676) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3676) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3676) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3676) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Proxy Gear Pro v2.1.rar
(PID) Process:(3676) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3676) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3676) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3676) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3676) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(3676) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF2C0000002C000000EC03000021020000
Executable files
3
Suspicious files
2
Text files
5
Unknown types
1

Dropped files

PID
Process
Filename
Type
3676WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3676.48996\Proxy Gear Pro v2.1\Proxy Gear Pro.exe
MD5:
SHA256:
3676WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3676.48996\Proxy Gear Pro v2.1\pgpro_masks.lsttext
MD5:
SHA256:
2876Proxy Gear Pro.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HHUAAB7W\pgpro[1].exeexecutable
MD5:
SHA256:
2612RegAsm.exeC:\Users\admin\AppData\Roaming\90059C37-1320-41A4-B58D-2B75A9850D2F\run.dattext
MD5:
SHA256:
3024pgpro.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HHUAAB7W\ad[1].gifimage
MD5:
SHA256:
3024pgpro.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GUFVP8I9\ad[1].htmhtml
MD5:
SHA256:
2876Proxy Gear Pro.exeC:\Users\admin\AppData\Local\Temp\pgpro.exeexecutable
MD5:
SHA256:
2612RegAsm.exeC:\Users\admin\AppData\Roaming\90059C37-1320-41A4-B58D-2B75A9850D2F\catalog.datbs
MD5:32D0AAE13696FF7F8AF33B2D22451028
SHA256:5347661365E7AD2C1ACC27AB0D150FFA097D9246BB3626FCA06989E976E8DD29
3676WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3676.48996\Proxy Gear Pro v2.1\antigate.keytext
MD5:81051BCC2CF1BEDF378224B0A93E2877
SHA256:7EB70257593DA06F682A3DDDA54A9D260D4FC514F645237F5CA74B08F8DA61A6
2612RegAsm.exeC:\Users\admin\AppData\Roaming\90059C37-1320-41A4-B58D-2B75A9850D2F\storage.datbinary
MD5:963D5E2C9C0008DFF05518B47C367A7F
SHA256:5EACF2974C9BB2C2E24CDC651C4840DD6F4B76A98F0E85E90279F1DBB2E6F3C0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
11
DNS requests
7
Threats
21

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2876
Proxy Gear Pro.exe
GET
200
185.104.29.84:80
http://omariodesigns.nl/abcaa/pgpro.exe
NL
executable
1.55 Mb
malicious
3024
pgpro.exe
GET
200
89.46.101.42:80
http://impuls.name/pgpro/updates.txt
RO
text
418 b
malicious
3024
pgpro.exe
GET
200
69.162.69.148:80
http://icanhazip.com/
US
text
14 b
shared
3024
pgpro.exe
GET
200
89.46.101.42:80
http://impuls.name/pgpro/ad.php
RO
html
420 b
malicious
3024
pgpro.exe
GET
200
89.46.101.42:80
http://impuls.name/pgpro/ad.gif
RO
image
33.9 Kb
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2612
RegAsm.exe
185.114.225.108:1231
omqriorat.ddns.net
i3D.net B.V
NL
malicious
2612
RegAsm.exe
8.8.8.8:53
Google Inc.
US
malicious
2876
Proxy Gear Pro.exe
185.104.29.84:80
omariodesigns.nl
Stichting DIGI NL
NL
malicious
3024
pgpro.exe
89.46.101.42:80
impuls.name
M247 Ltd
RO
malicious
3024
pgpro.exe
69.162.69.148:80
icanhazip.com
Limestone Networks, Inc.
US
suspicious

DNS requests

Domain
IP
Reputation
omariodesigns.nl
  • 185.104.29.84
malicious
icanhazip.com
  • 69.162.69.148
  • 69.162.69.147
  • 69.162.69.150
  • 69.162.69.149
shared
impuls.name
  • 89.46.101.42
malicious
omqriorat.ddns.net
  • 185.114.225.108
malicious

Threats

PID
Process
Class
Message
2876
Proxy Gear Pro.exe
Potential Corporate Privacy Violation
ET POLICY Autoit Windows Automation tool User-Agent in HTTP Request - Possibly Hostile
2876
Proxy Gear Pro.exe
A Network Trojan was detected
ET TROJAN AutoIt Downloading EXE - Likely Malicious
2876
Proxy Gear Pro.exe
A Network Trojan was detected
ET CURRENT_EVENTS Potential Dridex.Maldoc Minimal Executable Request
2876
Proxy Gear Pro.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3024
pgpro.exe
Potential Corporate Privacy Violation
ET MALWARE ProxyGearPro Proxy Tool PUA
3024
pgpro.exe
Attempted Information Leak
ET POLICY IP Check Domain (icanhazip. com in HTTP Host)
2612
RegAsm.exe
A Network Trojan was detected
SC BAD_UNKNOWN DYNAMIC_DNS Query to a Suspicious *.ddns.net Domain
2612
RegAsm.exe
A Network Trojan was detected
ET TROJAN Possible NanoCore C2 60B
3024
pgpro.exe
Potential Corporate Privacy Violation
ET MALWARE ProxyGearPro Proxy Tool PUA
2612
RegAsm.exe
A Network Trojan was detected
ET TROJAN Possible NanoCore C2 64B
No debug info