| File name: | Proxy Gear Pro v2.1.rar |
| Full analysis: | https://app.any.run/tasks/5a865b7f-1370-4a27-bd47-4b4ea6c7202e |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | August 02, 2018, 20:13:09 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | C1D65BDA8631860DA7E2DF2BE31F0FC2 |
| SHA1: | DFAC23B0BA522EDDA62ECE259DBBCD7972573835 |
| SHA256: | 86CD8B2ABD12A31CEF60DD0E4DBF49D4F6263B99CC50C8A648730C4211C69095 |
| SSDEEP: | 24576:6CmwcisMvlFNMdsR0QGVTp4TnCAA98Dh8hN1RM37bqb98Q3xlmdHMU7hR6PrTHVm:pmwcijF7CzALhkN1RM888mdd7hR6zM |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1044 | "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\WININET.dll",DispatchAPICall 1 | C:\Windows\system32\rundll32.exe | — | Proxy Gear Pro.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2612 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe | Proxy Gear Pro.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft .NET Assembly Registration Utility Exit code: 0 Version: 2.0.50727.5420 (Win7SP1.050727-5400) Modules
| |||||||||||||||
| 2876 | "C:\Users\admin\Desktop\Proxy Gear Pro v2.1\Proxy Gear Pro.exe" | C:\Users\admin\Desktop\Proxy Gear Pro v2.1\Proxy Gear Pro.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Proxy Gear Pro Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| 3024 | "C:\Users\admin\AppData\Local\Temp\pgpro.exe" | C:\Users\admin\AppData\Local\Temp\pgpro.exe | Proxy Gear Pro.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Proxy Gear Pro Exit code: 0 Version: 2.1.0.0 Modules
| |||||||||||||||
| 3676 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Proxy Gear Pro v2.1.rar" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| (PID) Process: | (3676) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3676) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3676) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3676) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Proxy Gear Pro v2.1.rar | |||
| (PID) Process: | (3676) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3676) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3676) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3676) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3676) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
| (PID) Process: | (3676) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF2C0000002C000000EC03000021020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3676 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3676.48996\Proxy Gear Pro v2.1\Proxy Gear Pro.exe | — | |
MD5:— | SHA256:— | |||
| 3676 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3676.48996\Proxy Gear Pro v2.1\pgpro_masks.lst | text | |
MD5:— | SHA256:— | |||
| 2876 | Proxy Gear Pro.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HHUAAB7W\pgpro[1].exe | executable | |
MD5:— | SHA256:— | |||
| 2612 | RegAsm.exe | C:\Users\admin\AppData\Roaming\90059C37-1320-41A4-B58D-2B75A9850D2F\run.dat | text | |
MD5:— | SHA256:— | |||
| 3024 | pgpro.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HHUAAB7W\ad[1].gif | image | |
MD5:— | SHA256:— | |||
| 3024 | pgpro.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GUFVP8I9\ad[1].htm | html | |
MD5:— | SHA256:— | |||
| 2876 | Proxy Gear Pro.exe | C:\Users\admin\AppData\Local\Temp\pgpro.exe | executable | |
MD5:— | SHA256:— | |||
| 2612 | RegAsm.exe | C:\Users\admin\AppData\Roaming\90059C37-1320-41A4-B58D-2B75A9850D2F\catalog.dat | bs | |
MD5:32D0AAE13696FF7F8AF33B2D22451028 | SHA256:5347661365E7AD2C1ACC27AB0D150FFA097D9246BB3626FCA06989E976E8DD29 | |||
| 3676 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3676.48996\Proxy Gear Pro v2.1\antigate.key | text | |
MD5:81051BCC2CF1BEDF378224B0A93E2877 | SHA256:7EB70257593DA06F682A3DDDA54A9D260D4FC514F645237F5CA74B08F8DA61A6 | |||
| 2612 | RegAsm.exe | C:\Users\admin\AppData\Roaming\90059C37-1320-41A4-B58D-2B75A9850D2F\storage.dat | binary | |
MD5:963D5E2C9C0008DFF05518B47C367A7F | SHA256:5EACF2974C9BB2C2E24CDC651C4840DD6F4B76A98F0E85E90279F1DBB2E6F3C0 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2876 | Proxy Gear Pro.exe | GET | 200 | 185.104.29.84:80 | http://omariodesigns.nl/abcaa/pgpro.exe | NL | executable | 1.55 Mb | malicious |
3024 | pgpro.exe | GET | 200 | 89.46.101.42:80 | http://impuls.name/pgpro/updates.txt | RO | text | 418 b | malicious |
3024 | pgpro.exe | GET | 200 | 69.162.69.148:80 | http://icanhazip.com/ | US | text | 14 b | shared |
3024 | pgpro.exe | GET | 200 | 89.46.101.42:80 | http://impuls.name/pgpro/ad.php | RO | html | 420 b | malicious |
3024 | pgpro.exe | GET | 200 | 89.46.101.42:80 | http://impuls.name/pgpro/ad.gif | RO | image | 33.9 Kb | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2612 | RegAsm.exe | 185.114.225.108:1231 | omqriorat.ddns.net | i3D.net B.V | NL | malicious |
2612 | RegAsm.exe | 8.8.8.8:53 | — | Google Inc. | US | malicious |
2876 | Proxy Gear Pro.exe | 185.104.29.84:80 | omariodesigns.nl | Stichting DIGI NL | NL | malicious |
3024 | pgpro.exe | 89.46.101.42:80 | impuls.name | M247 Ltd | RO | malicious |
3024 | pgpro.exe | 69.162.69.148:80 | icanhazip.com | Limestone Networks, Inc. | US | suspicious |
Domain | IP | Reputation |
|---|---|---|
omariodesigns.nl |
| malicious |
icanhazip.com |
| shared |
impuls.name |
| malicious |
omqriorat.ddns.net |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
2876 | Proxy Gear Pro.exe | Potential Corporate Privacy Violation | ET POLICY Autoit Windows Automation tool User-Agent in HTTP Request - Possibly Hostile |
2876 | Proxy Gear Pro.exe | A Network Trojan was detected | ET TROJAN AutoIt Downloading EXE - Likely Malicious |
2876 | Proxy Gear Pro.exe | A Network Trojan was detected | ET CURRENT_EVENTS Potential Dridex.Maldoc Minimal Executable Request |
2876 | Proxy Gear Pro.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
3024 | pgpro.exe | Potential Corporate Privacy Violation | ET MALWARE ProxyGearPro Proxy Tool PUA |
3024 | pgpro.exe | Attempted Information Leak | ET POLICY IP Check Domain (icanhazip. com in HTTP Host) |
2612 | RegAsm.exe | A Network Trojan was detected | SC BAD_UNKNOWN DYNAMIC_DNS Query to a Suspicious *.ddns.net Domain |
2612 | RegAsm.exe | A Network Trojan was detected | ET TROJAN Possible NanoCore C2 60B |
3024 | pgpro.exe | Potential Corporate Privacy Violation | ET MALWARE ProxyGearPro Proxy Tool PUA |
2612 | RegAsm.exe | A Network Trojan was detected | ET TROJAN Possible NanoCore C2 64B |