File name:

Proxy Scraper by xRisky v1.0.rar

Full analysis: https://app.any.run/tasks/08cf5f68-fdec-45f9-994b-45a25b662f73
Verdict: Malicious activity
Analysis date: March 02, 2022, 15:15:49
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

DD30ACE187B47932DF6AF155F488E261

SHA1:

24713922296BEA65B2A3F67F4CFD2BAEE610B3CE

SHA256:

A4C490BD626F6F513FBE70ED2F65557CF9D4CC6F173790357A46D4E7D1AB5D32

SSDEEP:

24576:mv9lAg3uYz+EJcUJV2TyrjFbugKNmlNZ3pVQi19iiKgixwkAJ9Kwe:QoYu8J8WHFbu3Uppem9Mx5we

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 2768)
      • Explorer.EXE (PID: 1108)
    • Application was dropped or rewritten from another process

      • Proxy Scraper by xRisky v1.0.exe (PID: 3544)
      • Proxy Scraper by xRisky v1.0.exe (PID: 2876)
    • Writes to a start menu file

      • Proxy Scraper by xRisky v1.0.exe (PID: 3544)
  • SUSPICIOUS

    • Checks supported languages

      • WinRAR.exe (PID: 2224)
      • Proxy Scraper by xRisky v1.0.exe (PID: 3544)
      • Proxy Scraper by xRisky v1.0.exe (PID: 2876)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2224)
    • Creates files in the user directory

      • Proxy Scraper by xRisky v1.0.exe (PID: 3544)
    • Writes to a desktop.ini file (may be used to cloak folders)

      • WinRAR.exe (PID: 2224)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 2224)
    • Reads the computer name

      • WinRAR.exe (PID: 2224)
      • Proxy Scraper by xRisky v1.0.exe (PID: 3544)
      • Proxy Scraper by xRisky v1.0.exe (PID: 2876)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 2224)
    • Reads default file associations for system extensions

      • Explorer.EXE (PID: 1108)
    • Creates a directory in Program Files

      • Proxy Scraper by xRisky v1.0.exe (PID: 2876)
  • INFO

    • Manual execution by user

      • Proxy Scraper by xRisky v1.0.exe (PID: 3544)
      • Proxy Scraper by xRisky v1.0.exe (PID: 2876)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
5
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs proxy scraper by xrisky v1.0.exe proxy scraper by xrisky v1.0.exe explorer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1108C:\Windows\Explorer.EXEC:\Windows\Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2224"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Proxy Scraper by xRisky v1.0.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2768"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2876"C:\Users\admin\Desktop\Proxy Scraper by xRisky v1.0\Proxy Scraper by xRisky v1.0.exe" C:\Users\admin\Desktop\Proxy Scraper by xRisky v1.0\Proxy Scraper by xRisky v1.0.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Description:
interface
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\proxy scraper by xrisky v1.0\proxy scraper by xrisky v1.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3544"C:\Users\admin\Desktop\Proxy Scraper by xRisky v1.0\Proxy Scraper by xRisky v1.0.exe" C:\Users\admin\Desktop\Proxy Scraper by xRisky v1.0\Proxy Scraper by xRisky v1.0.exe
Explorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
interface
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\proxy scraper by xrisky v1.0\proxy scraper by xrisky v1.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
6 691
Read events
6 618
Write events
73
Delete events
0

Modification events

(PID) Process:(2224) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2224) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2224) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2224) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2224) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2224) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Proxy Scraper by xRisky v1.0.rar
(PID) Process:(2224) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2224) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2224) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2224) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
7
Suspicious files
0
Text files
2
Unknown types
1

Dropped files

PID
Process
Filename
Type
2224WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2224.32391\Proxy Scraper by xRisky v1.0\Network\Extreme.Net.dllexecutable
MD5:4BD4346716370386491D6EBC4438B69D
SHA256:155E446000555C8EDAC8304CEF99C2CD54E8267981F1482D14A69C66575E6551
3544Proxy Scraper by xRisky v1.0.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Startup.lnklnk
MD5:
SHA256:
2224WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2224.32391\Proxy Scraper by xRisky v1.0\Proxy Scraper by xRisky v1.0.exeexecutable
MD5:
SHA256:
2224WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2224.32391\Proxy Scraper by xRisky v1.0\IronPython.dllexecutable
MD5:9A39A51E6DCB22B80DB481FBFBCD7826
SHA256:61B809B97DC878F42E85EE2C5D8471853527754E4F53B17C0507334C57E19E04
2224WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2224.32391\Proxy Scraper by xRisky v1.0\Network\Windows.Devices.WiFiDirect.dllexecutable
MD5:ABE5FB586235B03C38890CA88ECE6E92
SHA256:824AD0FFA3F77DB0D64FD2944E7F42FFEAD52DDB1376072E0213A11D97AE68D3
2224WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2224.32391\Proxy Scraper by xRisky v1.0\Virus Total\scan.txttext
MD5:2E99FBAF1AD4F921EBE1BA0ADB710C25
SHA256:F2F02C614C4A88B423AD0A404F7F5E7C1D33C5445E75F3D6F651AE6E791CDD57
2224WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2224.32391\Proxy Scraper by xRisky v1.0\Virus Total\desktop.iniini
MD5:C279803B27F13369AA54FC9B84B72468
SHA256:D80758A34364CAB9DE42FF6ED57BCC753A0936DDDDF9952C5B4FB9FF0D7966C9
2224WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2224.32391\Proxy Scraper by xRisky v1.0\xNet.dllexecutable
MD5:9A39A51E6DCB22B80DB481FBFBCD7826
SHA256:61B809B97DC878F42E85EE2C5D8471853527754E4F53B17C0507334C57E19E04
2224WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2224.32391\Proxy Scraper by xRisky v1.0\Network\System.Security.Cryptography.Algorithms.dllexecutable
MD5:8325FF9791B4D7ABF167FF1BE9D3CC95
SHA256:3944BDC2621E3C9E6AE08FC69F72E15428ECBFC0666A97139EE38E50896364DE
2224WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2224.32391\Proxy Scraper by xRisky v1.0\msstdfmt.dllexecutable
MD5:1E27A0F62EBE8277C61B89C3747CC45D
SHA256:74EF23860B9ED15587EAE06670E83ABAC1928B502DAD244875713D127D83A1DF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info