File name:

Freebitco.inHack2018.v3.zip

Full analysis: https://app.any.run/tasks/46853aea-ed68-4d60-8ec6-94d765ef7a84
Verdict: Malicious activity
Analysis date: October 26, 2018, 16:09:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

E4FAF0E3EA5FC99C9DEDED094BCA4508

SHA1:

5B78ABE09D39577848DA114A70E0CB66A65DC3E5

SHA256:

A7A889F4F9E0FCD4823E8C3A58D3C13448BEBE33FFD3F4A439999514785AC6BB

SSDEEP:

6144:UnTy3+5eYx1eEqj852os139ni+VM9TG0acMqbAk6NAGGOzxm6a:736KEqjkfs139ni+10acMNknGGOzxm6a

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3388)
    • Application was dropped or rewritten from another process

      • Freebitco.in Hack 2018.exe (PID: 3324)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2900)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • WinRAR.exe (PID: 2900)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2018:10:22 17:31:04
ZipCRC: 0xfdb9e8d5
ZipCompressedSize: 188525
ZipUncompressedSize: 307712
ZipFileName: Freebitco.in Hack 2018.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs freebitco.in hack 2018.exe

Process information

PID
CMD
Path
Indicators
Parent process
2900"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Freebitco.inHack2018.v3.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3324"C:\Users\admin\Desktop\Freebitco.inHack2018.v3\Freebitco.in Hack 2018.exe" C:\Users\admin\Desktop\Freebitco.inHack2018.v3\Freebitco.in Hack 2018.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Freebitco.in Hack 2018
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\freebitco.inhack2018.v3\freebitco.in hack 2018.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3388"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe14_ Global\UsGthrCtrlFltPipeMssGthrPipe14 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
707
Read events
674
Write events
33
Delete events
0

Modification events

(PID) Process:(2900) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2900) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2900) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2900) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Freebitco.inHack2018.v3.zip
(PID) Process:(2900) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2900) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2900) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2900) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2900) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Freebitco.inHack2018.v3
(PID) Process:(2900) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
2
Suspicious files
0
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
2900WinRAR.exeC:\Users\admin\Desktop\Freebitco.inHack2018.v3\System.Net.Http.dllexecutable
MD5:86905201FA4EFFCB1796D38A07CF0EB0
SHA256:AEAB880E80F9BA7FDD5CF89ACE4F6C628222937D6B1E1B5CCC2517330D64D3C3
2900WinRAR.exeC:\Users\admin\Desktop\Freebitco.inHack2018.v3\Freebitco.in Hack 2018.exeexecutable
MD5:AB19E928C8D688770E94F58B92DA4164
SHA256:4A8090E108B4A3D3F8981C105031C8075628C2065FDB798DE161FEA52484E149
2900WinRAR.exeC:\Users\admin\Desktop\Freebitco.inHack2018.v3\scar5tf2_vcV_icon.icoimage
MD5:7A4323F15D14EBD8C292BA857E60E170
SHA256:BA71899FC2CA4735A063AF4DA3DA3EEF1A931F5F2E2BE18BE75E7D7E58C1B48A
2900WinRAR.exeC:\Users\admin\Desktop\Freebitco.inHack2018.v3\Freebitco.in Hack 2018.exe.configxml
MD5:C4C1C9F8C1A771D7AC1012C8B2AA2579
SHA256:73DDB6CDF45BE4E473A84A3C4838EDF0CC7C9433211935A1A8A70AFE88A57833
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
4
DNS requests
1
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3324
Freebitco.in Hack 2018.exe
GET
200
172.217.22.132:80
http://www.google.com/
US
html
46.2 Kb
malicious
3324
Freebitco.in Hack 2018.exe
GET
200
172.217.22.132:80
http://www.google.com/
US
html
46.2 Kb
malicious
3324
Freebitco.in Hack 2018.exe
GET
200
172.217.22.132:80
http://www.google.com/
US
html
46.2 Kb
malicious
3324
Freebitco.in Hack 2018.exe
GET
200
172.217.22.132:80
http://www.google.com/
US
html
46.1 Kb
malicious
3324
Freebitco.in Hack 2018.exe
GET
200
172.217.22.132:80
http://www.google.com/
US
html
46.1 Kb
malicious
3324
Freebitco.in Hack 2018.exe
GET
200
172.217.22.132:80
http://www.google.com/
US
html
46.2 Kb
malicious
3324
Freebitco.in Hack 2018.exe
GET
200
172.217.22.132:80
http://www.google.com/
US
html
46.2 Kb
malicious
3324
Freebitco.in Hack 2018.exe
GET
172.217.22.132:80
http://www.google.com/
US
malicious
3324
Freebitco.in Hack 2018.exe
GET
172.217.22.132:80
http://www.google.com/
US
malicious
3324
Freebitco.in Hack 2018.exe
GET
172.217.22.132:80
http://www.google.com/
US
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3324
Freebitco.in Hack 2018.exe
172.217.22.132:80
www.google.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
www.google.com
  • 172.217.22.132
malicious

Threats

PID
Process
Class
Message
3324
Freebitco.in Hack 2018.exe
Potentially Bad Traffic
ET WEB_CLIENT SUSPICIOUS Possible automated connectivity check (www.google.com)
No debug info