File name:

neuro stresser v4.zip

Full analysis: https://app.any.run/tasks/58533b2e-4c3a-417c-97c1-ac59fb92f64e
Verdict: Suspicious activity
Analysis date: June 27, 2019, 02:01:34
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

2708924522F42DAA955E4D61FCD6988D

SHA1:

6E0C1C0AA72EA7FD05AA3A3C1D2ECA6C80BCE643

SHA256:

9A9EA2733E1BBF8AA82FD499600B183C556E29257260D5086C3C9D376B365A63

SSDEEP:

98304:Q2AVQp1YMHHTInKzlCGm78G9NDZpCiSrZUjmm8PZudq:Q7QPHHTIKxCD78+NDZplg6am0uA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • Neuro Stresser.exe (PID: 2888)
    • Application was dropped or rewritten from another process

      • Neuro Stresser.exe (PID: 2888)
  • SUSPICIOUS

    • Reads Environment values

      • Neuro Stresser.exe (PID: 2888)
    • Executable content was dropped or overwritten

      • Neuro Stresser.exe (PID: 2888)
      • WinRAR.exe (PID: 3532)
    • Application launched itself

      • WinRAR.exe (PID: 3064)
  • INFO

    • Reads settings of System Certificates

      • Neuro Stresser.exe (PID: 2888)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 788
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2019:06:27 03:09:02
ZipCRC: 0xa6c54be4
ZipCompressedSize: 4168869
ZipUncompressedSize: 4174459
ZipFileName: V4.0.0.0.zip
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
3
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start winrar.exe no specs winrar.exe neuro stresser.exe

Process information

PID
CMD
Path
Indicators
Parent process
2888"C:\Users\admin\AppData\Local\Temp\Rar$EXa3532.45198\Neuro Stresser.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3532.45198\Neuro Stresser.exe
WinRAR.exe
User:
admin
Company:
Neuro Services
Integrity Level:
MEDIUM
Description:
Neuro Stresser
Exit code:
0
Version:
3.9.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3532.45198\neuro stresser.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3064"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\neuro stresser v4.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3532"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Rar$DIb3064.43993\V4.0.0.0.zipC:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
Total events
940
Read events
887
Write events
53
Delete events
0

Modification events

(PID) Process:(3064) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3064) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3064) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3064) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\neuro stresser v4.zip
(PID) Process:(3064) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3064) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3064) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3064) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3064) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(3064) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
8
Suspicious files
1
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
3532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3532.45198\Neuro Stresser.exeexecutable
MD5:
SHA256:
3064WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIb3064.43993\V4.0.0.0.zipcompressed
MD5:
SHA256:
3532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3532.45198\Neuro Stresser.exe.configxml
MD5:
SHA256:
3532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3532.45198\System.Net.Http.Primitives.dllexecutable
MD5:
SHA256:
3532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3532.45198\System.Net.Http.Extensions.dllexecutable
MD5:
SHA256:
3532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3532.45198\Microsoft.Threading.Tasks.Extensions.dllexecutable
MD5:5E195F1C9B62F8037BF763BCF3702684
SHA256:7C1CC8F7445696648701299C132D98CFD861771042DF1D5471354E539AD35AC2
2888Neuro Stresser.exeC:\Users\admin\AppData\Local\Temp\Protectc7229c0d.dllexecutable
MD5:C7229C0D28EEF84F1A48A445023C0F8D
SHA256:996356F0CE4960208C85AD0C1287768EEE190703EA2B93B5C5BEAA6010424349
3532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3532.45198\Microsoft.Threading.Tasks.dllexecutable
MD5:F725173A7B47E909F98A5079FD846106
SHA256:26E67B42CE9AE8581BC452FF0F99807166BADB416BC4B410D99E93A9D09A220A
3532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3532.45198\Newtonsoft.Json.dllexecutable
MD5:F33CBE589B769956284868104686CC2D
SHA256:973FD70CE48E5AC433A101B42871680C51E2FEBA2AEEC3D400DEA4115AF3A278
3532WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3532.45198\SafeGuard.dllexecutable
MD5:3307FC407D88BA40ABEAC87266F4558D
SHA256:B215110D42BDEC6069D1328E429C959F68C1BEE08333C4852BD3F5299B95173F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
4
Threats
3

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2888
Neuro Stresser.exe
50.19.247.198:443
api.ipify.org
Amazon.com, Inc.
US
shared
2888
Neuro Stresser.exe
104.27.147.240:443
neuroservices.co.uk
Cloudflare Inc
US
shared
2888
Neuro Stresser.exe
104.31.95.75:443
safeguardauth.us
Cloudflare Inc
US
shared

DNS requests

Domain
IP
Reputation
api.ipify.org
  • 50.19.247.198
  • 54.235.124.112
  • 23.23.243.154
  • 54.243.198.12
  • 107.22.215.20
  • 50.16.229.140
  • 54.243.147.226
  • 23.21.121.219
shared
safeguardauth.us
  • 104.31.95.75
  • 104.31.94.75
unknown
www.google.com
  • 172.217.16.164
malicious
neuroservices.co.uk
  • 104.27.147.240
  • 104.27.146.240
unknown

Threats

PID
Process
Class
Message
2888
Neuro Stresser.exe
Misc activity
SUSPICIOUS [PTsecurity] ipify.org External IP Check
2888
Neuro Stresser.exe
Misc activity
SUSPICIOUS [PTsecurity] ipify.org External IP Check
1 ETPRO signatures available at the full report
No debug info