| File name: | AntiPublic.zip |
| Full analysis: | https://app.any.run/tasks/d20bed2f-71c9-4375-8790-d37644529b41 |
| Verdict: | Malicious activity |
| Threats: | AZORult can steal banking information, including passwords and credit card details, as well as cryptocurrency. This constantly updated information stealer malware should not be taken lightly, as it continues to be an active threat. |
| Analysis date: | September 17, 2019, 13:45:59 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 9E936E6BE4DEBDC473C917BFD4CC8DF6 |
| SHA1: | 503B38EA4B96AA025BE963BA1C36432231129915 |
| SHA256: | 8C3E0C8F8A2E23A9AEF45E65C5F027771ED652F548B8907E6AA5731F7B05D099 |
| SSDEEP: | 24576:llfmtBoVjv0Barxn9HrRT3JFpNwL1OeSTXgVDeG/7:lJ6uv0BalnR9JFYJOev5bD |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2018:05:26 00:12:04 |
| ZipCRC: | 0xc96ee4a8 |
| ZipCompressedSize: | 12185 |
| ZipUncompressedSize: | 28160 |
| ZipFileName: | AltoControls.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 664 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3096.27282\AntiPublic.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3096.27282\AntiPublic.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| 684 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3016.24780\AntiPublic Updater.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3016.24780\AntiPublic Updater.exe | WinRAR.exe | ||||||||||||
User: admin Company: Newtonsoft Integrity Level: MEDIUM Description: Json.NET Exit code: 0 Version: 9.0.1.19813 Modules
| |||||||||||||||
| 1344 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3016.19552\AntiPublic.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3016.19552\AntiPublic.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| 2052 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2988 CREDAT:71937 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2084 | C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe -Embedding | C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe | — | svchost.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: MEDIUM Description: Adobe® Flash® Player Installer/Uninstaller 26.0 r0 Exit code: 0 Version: 26,0,0,131 Modules
| |||||||||||||||
| 2236 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3288 CREDAT:71937 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2320 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3016.12356\AntiPublic.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3016.12356\AntiPublic.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2492 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3016.17039\AntiPublic Updater.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3016.17039\AntiPublic Updater.exe | WinRAR.exe | ||||||||||||
User: admin Company: Newtonsoft Integrity Level: MEDIUM Description: Json.NET Exit code: 0 Version: 9.0.1.19813 Modules
| |||||||||||||||
| 2912 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3016.12063\ConsoleRegChecker.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3016.12063\ConsoleRegChecker.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: ConsoleRegChecker Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2988 | "C:\Program Files\Internet Explorer\iexplore.exe" -nohome | C:\Program Files\Internet Explorer\iexplore.exe | AntiPublic.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 1 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3016) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3016) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3016) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3016) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\AntiPublic.zip | |||
| (PID) Process: | (3016) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3016) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3016) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3016) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3016) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3016) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3016 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3016.48931\en\AntiPublic.resources.dll | executable | |
MD5:— | SHA256:— | |||
| 3016 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3016.48931\AntiPublic.exe | executable | |
MD5:— | SHA256:— | |||
| 3016 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3016.12063\en\AntiPublic.resources.dll | executable | |
MD5:— | SHA256:— | |||
| 3016 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3016.48931\Newtonsoft.Json.dll | executable | |
MD5:5AFDA7C7D4F7085E744C2E7599279DB3 | SHA256:F58C374FFCAAE4E36D740D90FBF7FE70D0ABB7328CD9AF3A0A7B70803E994BA4 | |||
| 3016 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3016.48931\AltoControls.dll | executable | |
MD5:B581A0648CE87B6E293E45A87D02C4A1 | SHA256:3252DC102E53EE98CEEE6B5945AD2A9A552831C581EEAD76BD22C30C5C2633D5 | |||
| 3016 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3016.48931\GemBox.Email.dll | executable | |
MD5:3657F2F4783FC9D9505B8C137AABA060 | SHA256:A5899F6D6C6F3944DEC97CA32B4A915606EE7154ABCEC29020AF3C21AE9B3274 | |||
| 3016 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3016.48931\GemBox.Email.xml | xml | |
MD5:8655FDE8790C59D030ADEB2785272E11 | SHA256:50E6A3EFB27C484E370F35BDD1441520AE9C5642277E0B62CB3B42AE7D6A1146 | |||
| 3016 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3016.48931\ru-RU\AntiPublic.resources.dll | executable | |
MD5:523B1F726C98B6F45D7E3D785AC0FC38 | SHA256:E27D305EFC4EB3B3387FD02A7BE6D857E54F537F54A7158E0C17B40CFE8CDB2D | |||
| 3016 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3016.12063\AltoControls.dll | executable | |
MD5:B581A0648CE87B6E293E45A87D02C4A1 | SHA256:3252DC102E53EE98CEEE6B5945AD2A9A552831C581EEAD76BD22C30C5C2633D5 | |||
| 3016 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3016.48931\AntiPublic Updater.exe | executable | |
MD5:6CAE94E55820679E220B859ADB2A8984 | SHA256:228B01F9078EA70737E17F75D08567B92AB9D226899D63116FA407CBF34C0350 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3312 | AntiPublic.exe | GET | 200 | 144.76.190.197:80 | http://myrz.org/api/check.php?key=c94bbf3863c96496ab5b87455ee699a1&plus=1 | DE | text | 96 b | whitelisted |
3312 | AntiPublic.exe | GET | 200 | 144.76.190.197:80 | http://myrz.org/api/check.php?key=c94bbf3863c96496ab5b87455ee699a1&plus=1 | DE | text | 96 b | whitelisted |
1344 | AntiPublic.exe | GET | 200 | 144.76.190.197:80 | http://myrz.org/api/check_updates.php?do=version | DE | text | 18 b | whitelisted |
3312 | AntiPublic.exe | GET | 200 | 144.76.190.197:80 | http://myrz.org/api/check.php?key=c94bbf3863c96496ab5b87455ee699a1&plus=1 | DE | text | 96 b | whitelisted |
1344 | AntiPublic.exe | GET | 200 | 144.76.190.197:80 | http://myrz.org/api/check.php?key=c94bbf3863c96496ab5b87455ee699a1&plus=1 | DE | text | 96 b | whitelisted |
1344 | AntiPublic.exe | GET | 200 | 144.76.190.197:80 | http://myrz.org/api/check.php?key=c94bbf3863c96496ab5b87455ee699a1&plus=1 | DE | text | 96 b | whitelisted |
664 | AntiPublic.exe | GET | 200 | 144.76.190.197:80 | http://myrz.org/api/check.php?key=c94bbf3863c96496ab5b87455ee699a1&plus=1 | DE | text | 96 b | whitelisted |
684 | AntiPublic Updater.exe | GET | 200 | 144.76.190.197:80 | http://myrz.org/check_updates.php | DE | text | 79 b | whitelisted |
664 | AntiPublic.exe | GET | 200 | 144.76.190.197:80 | http://myrz.org/api/check.php?key=c94bbf3863c96496ab5b87455ee699a1&plus=1 | DE | text | 96 b | whitelisted |
2236 | iexplore.exe | GET | 200 | 144.76.190.197:80 | http://myrz.org/AntiPublic.zip | DE | compressed | 677 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3312 | AntiPublic.exe | 144.76.190.197:80 | myrz.org | Hetzner Online GmbH | DE | suspicious |
1344 | AntiPublic.exe | 144.76.190.197:80 | myrz.org | Hetzner Online GmbH | DE | suspicious |
2988 | iexplore.exe | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
2052 | iexplore.exe | 178.32.0.172:443 | lolzteam.net | OVH SAS | FR | unknown |
2052 | iexplore.exe | 216.58.207.42:443 | fonts.googleapis.com | Google Inc. | US | whitelisted |
2052 | iexplore.exe | 172.217.22.99:443 | fonts.gstatic.com | Google Inc. | US | whitelisted |
2052 | iexplore.exe | 88.212.201.207:443 | counter.yadro.ru | United Network LLC | RU | unknown |
2052 | iexplore.exe | 151.101.112.193:443 | i.imgur.com | Fastly | US | malicious |
2988 | iexplore.exe | 178.32.0.172:443 | lolzteam.net | OVH SAS | FR | unknown |
684 | AntiPublic Updater.exe | 144.76.190.197:80 | myrz.org | Hetzner Online GmbH | DE | suspicious |
Domain | IP | Reputation |
|---|---|---|
tembumgo.pw |
| malicious |
myrz.org |
| whitelisted |
www.bing.com |
| whitelisted |
lolzteam.net |
| whitelisted |
fonts.googleapis.com |
| whitelisted |
code.jquery.com |
| whitelisted |
fonts.gstatic.com |
| whitelisted |
i.imgur.com |
| malicious |
counter.yadro.ru |
| whitelisted |
mc.yandex.ru |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1060 | svchost.exe | Potentially Bad Traffic | ET DNS Query to a *.pw domain - Likely Hostile |
3068 | AntiPublic.exe | A Network Trojan was detected | AV TROJAN Azorult CnC Beacon |
3068 | AntiPublic.exe | A Network Trojan was detected | MALWARE [PTsecurity] AZORult.Stealer HTTP Header |
3068 | AntiPublic.exe | A Network Trojan was detected | MALWARE [PTsecurity] AZORult Request |
3068 | AntiPublic.exe | Potentially Bad Traffic | ET INFO HTTP Request to a *.pw domain |
3156 | AntiPublic.exe | A Network Trojan was detected | AV TROJAN Azorult CnC Beacon |
3156 | AntiPublic.exe | A Network Trojan was detected | MALWARE [PTsecurity] AZORult.Stealer HTTP Header |
3156 | AntiPublic.exe | A Network Trojan was detected | MALWARE [PTsecurity] AZORult Request |
3156 | AntiPublic.exe | Potentially Bad Traffic | ET INFO HTTP Request to a *.pw domain |
2492 | AntiPublic Updater.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |