File name:

Sentry MBA 1.4.1.zip

Full analysis: https://app.any.run/tasks/c54851fa-62c3-4b19-9fd2-3aee53964e8f
Verdict: Malicious activity
Analysis date: June 22, 2019, 14:16:39
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

A9F5E4F078BDD49B428464821B798817

SHA1:

5875434FEF809DC35918537F9C730B29CD14C548

SHA256:

9A6E408ECC41B445D7A1D7CE9A95576EFD53DF001CEE0B5C56CEF3588EF823F0

SSDEEP:

196608:ffJN9Jsq4Y8meF0ubF1gGdBhxfDoAw8hRndSuuwkNi+UgpQD4Pn7B4oykNi+UD:fD9H8BGYF1fdBzM/8fd2Ngc2opNgD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 2920)
    • Application was dropped or rewritten from another process

      • Sentry_MBA.exe (PID: 3800)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1336)
    • Checks for external IP

      • Sentry_MBA.exe (PID: 3800)
  • INFO

    • Manual execution by user

      • Sentry_MBA.exe (PID: 3800)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (33.3)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2019:01:04 17:36:20
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Sentry MBA 1.4.1/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs sentry_mba.exe

Process information

PID
CMD
Path
Indicators
Parent process
1336"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Sentry MBA 1.4.1.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2920"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3800"C:\Users\admin\Desktop\Sentry MBA 1.4.1\Sentry_MBA.exe" C:\Users\admin\Desktop\Sentry MBA 1.4.1\Sentry_MBA.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Sentry MBA
Exit code:
0
Version:
1.4.1.9619
Modules
Images
c:\users\admin\desktop\sentry mba 1.4.1\sentry_mba.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
779
Read events
769
Write events
10
Delete events
0

Modification events

(PID) Process:(1336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1336) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Sentry MBA 1.4.1.zip
(PID) Process:(1336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2920) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2920) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
3
Suspicious files
32
Text files
128
Unknown types
45

Dropped files

PID
Process
Filename
Type
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\ipfilter.dat
MD5:
SHA256:
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\Sites.initext
MD5:
SHA256:
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\FAQ.txttext
MD5:29701FB5186BBF5673A029FE508F13FA
SHA256:694638E9CAF4ED5963B4B53629BC2D9ECD765AA6125B3B2340C8BDD204E115B5
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\ImageData.datbinary
MD5:6E76ED376393DA767F2C3E46A659D763
SHA256:E60CC1B7BDFADA87ED0E45C31A72051D53E729F8C257F83228B7E1E3F1E61B16
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\MyList.initext
MD5:
SHA256:
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\Settings.initext
MD5:
SHA256:
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\GlobalKeys.inihtml
MD5:0749104405730984191869863D76C886
SHA256:5ADB04CC7E02649DDE48DB7B08C2409F9A641070DDD119E28194ED5664E01C80
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\Sentry_MBA_1.0_Changes.pdfpdf
MD5:E8CAA12CFA0E41BAE3C5BFE5831DE3F5
SHA256:7BAF072B1751593F567D58F979ADFB337DD97D16B192713360080DB770F30B4D
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\tessdata\cp1.normprototext
MD5:58C6A7CC3DF646E3FE1FC96042DCE431
SHA256:FFE0F0FB6A108233523B5623367D489390EDC7C90951285DB538EC52A5EA6E2D
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\Sentry_MBA.exeexecutable
MD5:4D1B874FDF4D3C6ABC5AEBF4959AE6E5
SHA256:273656004E557B0991885D4CFF58507C590C3D6F5ED24E315ADD22453E6CF4AB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3800
Sentry_MBA.exe
GET
200
216.146.43.71:80
http://checkip.dyndns.org/
US
html
106 b
shared
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3800
Sentry_MBA.exe
216.146.43.71:80
checkip.dyndns.org
Dynamic Network Services, Inc.
US
shared

DNS requests

Domain
IP
Reputation
checkip.dyndns.org
  • 216.146.43.71
  • 131.186.113.70
  • 216.146.43.70
  • 162.88.193.70
shared

Threats

PID
Process
Class
Message
1068
svchost.exe
Misc activity
ET INFO DYNAMIC_DNS Query to *.dyndns. Domain
1068
svchost.exe
Misc activity
AV INFO Query to checkip.dyndns. Domain
3800
Sentry_MBA.exe
Potential Corporate Privacy Violation
ET POLICY External IP Lookup - checkip.dyndns.org
3800
Sentry_MBA.exe
Potentially Bad Traffic
ET POLICY DynDNS CheckIp External IP Address Server Response
No debug info