File name:

Sentry MBA 1.4.1.zip

Full analysis: https://app.any.run/tasks/c54851fa-62c3-4b19-9fd2-3aee53964e8f
Verdict: Malicious activity
Analysis date: June 22, 2019, 14:16:39
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

A9F5E4F078BDD49B428464821B798817

SHA1:

5875434FEF809DC35918537F9C730B29CD14C548

SHA256:

9A6E408ECC41B445D7A1D7CE9A95576EFD53DF001CEE0B5C56CEF3588EF823F0

SSDEEP:

196608:ffJN9Jsq4Y8meF0ubF1gGdBhxfDoAw8hRndSuuwkNi+UgpQD4Pn7B4oykNi+UD:fD9H8BGYF1fdBzM/8fd2Ngc2opNgD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 2920)
    • Application was dropped or rewritten from another process

      • Sentry_MBA.exe (PID: 3800)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1336)
    • Checks for external IP

      • Sentry_MBA.exe (PID: 3800)
  • INFO

    • Manual execution by user

      • Sentry_MBA.exe (PID: 3800)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (33.3)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2019:01:04 17:36:20
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Sentry MBA 1.4.1/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs sentry_mba.exe

Process information

PID
CMD
Path
Indicators
Parent process
1336"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Sentry MBA 1.4.1.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2920"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3800"C:\Users\admin\Desktop\Sentry MBA 1.4.1\Sentry_MBA.exe" C:\Users\admin\Desktop\Sentry MBA 1.4.1\Sentry_MBA.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Sentry MBA
Exit code:
0
Version:
1.4.1.9619
Modules
Images
c:\users\admin\desktop\sentry mba 1.4.1\sentry_mba.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
779
Read events
769
Write events
10
Delete events
0

Modification events

(PID) Process:(1336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1336) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Sentry MBA 1.4.1.zip
(PID) Process:(1336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2920) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2920) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
3
Suspicious files
32
Text files
128
Unknown types
45

Dropped files

PID
Process
Filename
Type
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\ipfilter.dat
MD5:
SHA256:
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\MyList.initext
MD5:42CBAE6F1BEF61AF7EEA6E779A84FFA6
SHA256:B6454C5BB74291937FD2E883211010A7C199C6F8A9184213224E98870C722ADF
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\Settings.initext
MD5:8E523BE1CA31C6D970933C76B5F67B05
SHA256:997C110A8B422DEA00D63E4692B7A22A0D4EDEC00C4906FCA8273E0F28304988
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\Sites.initext
MD5:FF4ECFF24E63BE75A30097FD04C09407
SHA256:BFD58718FB2568F33559D322A819814C98CCDDD4A3E9DACA52996F142BDF1EBF
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\FAQ.txttext
MD5:29701FB5186BBF5673A029FE508F13FA
SHA256:694638E9CAF4ED5963B4B53629BC2D9ECD765AA6125B3B2340C8BDD204E115B5
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\History.initext
MD5:D0DBB4B69023577481808EA914FDF880
SHA256:3F3AE6F85D022C669F9977E4C7A5AB80A1AB61C4A3C782E96FB65B1BBAEF318A
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\GlobalKeys.inihtml
MD5:0749104405730984191869863D76C886
SHA256:5ADB04CC7E02649DDE48DB7B08C2409F9A641070DDD119E28194ED5664E01C80
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\MBA VARIABLES.pdfpdf
MD5:DCB55D5B4FAFA1BC343BD57BA1D808A9
SHA256:7B9F5D1FF02F7AFFABF0F0F1E029553305ABAEA5619701EF0F6475E969B32DFC
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\ImageData.datbinary
MD5:6E76ED376393DA767F2C3E46A659D763
SHA256:E60CC1B7BDFADA87ED0E45C31A72051D53E729F8C257F83228B7E1E3F1E61B16
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\Sentry_MBA_ReadMe.txttext
MD5:95CCE1F8D2411011956D89F74AFB4D9E
SHA256:BC1B11D8E87C0CFEE71ACC5A903ED4A0B71A2ECEB34BADC30FABD1594845F249
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3800
Sentry_MBA.exe
GET
200
216.146.43.71:80
http://checkip.dyndns.org/
US
html
106 b
shared
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3800
Sentry_MBA.exe
216.146.43.71:80
checkip.dyndns.org
Dynamic Network Services, Inc.
US
shared

DNS requests

Domain
IP
Reputation
checkip.dyndns.org
  • 216.146.43.71
  • 131.186.113.70
  • 216.146.43.70
  • 162.88.193.70
shared

Threats

PID
Process
Class
Message
1068
svchost.exe
Misc activity
ET INFO DYNAMIC_DNS Query to *.dyndns. Domain
1068
svchost.exe
Misc activity
AV INFO Query to checkip.dyndns. Domain
3800
Sentry_MBA.exe
Potential Corporate Privacy Violation
ET POLICY External IP Lookup - checkip.dyndns.org
3800
Sentry_MBA.exe
Potentially Bad Traffic
ET POLICY DynDNS CheckIp External IP Address Server Response
No debug info