File name:

Sentry MBA 1.4.1.zip

Full analysis: https://app.any.run/tasks/c54851fa-62c3-4b19-9fd2-3aee53964e8f
Verdict: Malicious activity
Analysis date: June 22, 2019, 14:16:39
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

A9F5E4F078BDD49B428464821B798817

SHA1:

5875434FEF809DC35918537F9C730B29CD14C548

SHA256:

9A6E408ECC41B445D7A1D7CE9A95576EFD53DF001CEE0B5C56CEF3588EF823F0

SSDEEP:

196608:ffJN9Jsq4Y8meF0ubF1gGdBhxfDoAw8hRndSuuwkNi+UgpQD4Pn7B4oykNi+UD:fD9H8BGYF1fdBzM/8fd2Ngc2opNgD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 2920)
    • Application was dropped or rewritten from another process

      • Sentry_MBA.exe (PID: 3800)
  • SUSPICIOUS

    • Checks for external IP

      • Sentry_MBA.exe (PID: 3800)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1336)
  • INFO

    • Manual execution by user

      • Sentry_MBA.exe (PID: 3800)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (33.3)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2019:01:04 17:36:20
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Sentry MBA 1.4.1/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs sentry_mba.exe

Process information

PID
CMD
Path
Indicators
Parent process
1336"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Sentry MBA 1.4.1.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2920"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3800"C:\Users\admin\Desktop\Sentry MBA 1.4.1\Sentry_MBA.exe" C:\Users\admin\Desktop\Sentry MBA 1.4.1\Sentry_MBA.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Sentry MBA
Exit code:
0
Version:
1.4.1.9619
Modules
Images
c:\users\admin\desktop\sentry mba 1.4.1\sentry_mba.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
779
Read events
769
Write events
10
Delete events
0

Modification events

(PID) Process:(1336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1336) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Sentry MBA 1.4.1.zip
(PID) Process:(1336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2920) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2920) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
3
Suspicious files
32
Text files
128
Unknown types
45

Dropped files

PID
Process
Filename
Type
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\ipfilter.dat
MD5:
SHA256:
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\MyList.initext
MD5:
SHA256:
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\Settings.initext
MD5:
SHA256:
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\Sites.initext
MD5:
SHA256:
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\tessdata\cp1.DangAmbigstext
MD5:0BD043AFE4C95110C2CB0B88CAB29453
SHA256:C304E6674842AB688C230181AFA8E6FF88E6F8F44CAB6621021B5442EF3CC7FB
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\History.initext
MD5:D0DBB4B69023577481808EA914FDF880
SHA256:3F3AE6F85D022C669F9977E4C7A5AB80A1AB61C4A3C782E96FB65B1BBAEF318A
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\MBA VARIABLES.pdfpdf
MD5:DCB55D5B4FAFA1BC343BD57BA1D808A9
SHA256:7B9F5D1FF02F7AFFABF0F0F1E029553305ABAEA5619701EF0F6475E969B32DFC
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\tessdata\cp1.inttempbinary
MD5:3BAAFA99D050A639BC508AF12464A417
SHA256:E47AC5AD3BDCA1BCBEAAAF3EDEFD0AB8E50E3EAE3B8027BF5FE5E05A005B34C6
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\Sentry_MBA.exeexecutable
MD5:4D1B874FDF4D3C6ABC5AEBF4959AE6E5
SHA256:273656004E557B0991885D4CFF58507C590C3D6F5ED24E315ADD22453E6CF4AB
1336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1336.4153\Sentry MBA 1.4.1\Sentry_MBA_ReadMe.txttext
MD5:95CCE1F8D2411011956D89F74AFB4D9E
SHA256:BC1B11D8E87C0CFEE71ACC5A903ED4A0B71A2ECEB34BADC30FABD1594845F249
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3800
Sentry_MBA.exe
GET
200
216.146.43.71:80
http://checkip.dyndns.org/
US
html
106 b
shared
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3800
Sentry_MBA.exe
216.146.43.71:80
checkip.dyndns.org
Dynamic Network Services, Inc.
US
shared

DNS requests

Domain
IP
Reputation
checkip.dyndns.org
  • 216.146.43.71
  • 131.186.113.70
  • 216.146.43.70
  • 162.88.193.70
shared

Threats

PID
Process
Class
Message
1068
svchost.exe
Misc activity
ET INFO DYNAMIC_DNS Query to *.dyndns. Domain
1068
svchost.exe
Misc activity
AV INFO Query to checkip.dyndns. Domain
3800
Sentry_MBA.exe
Potential Corporate Privacy Violation
ET POLICY External IP Lookup - checkip.dyndns.org
3800
Sentry_MBA.exe
Potentially Bad Traffic
ET POLICY DynDNS CheckIp External IP Address Server Response
No debug info