File name:

FaucetCollector v2.1.2 cracked.zip

Full analysis: https://app.any.run/tasks/84829bc5-45bd-49db-a77c-edae0ec49167
Verdict: Malicious activity
Analysis date: December 01, 2018, 21:00:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

FC7AC3E6FC3D43AABA242DF2BCFE9A2E

SHA1:

8835DDDF24DC330D201789EF362BE18CD5444ADE

SHA256:

AAEE94670AD85F5E5185C79F7ABB174B8CC22BC8F3FB463B11BD2437799DC799

SSDEEP:

393216:4zesnUjwGMIOiu/+P1vhJmJYlJQv2CBrK4CBr/F:4pemn2tr7JKnsFBF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • FaucetCollector.exe (PID: 2864)
    • Loads dropped or rewritten executable

      • FaucetCollector.exe (PID: 2864)
      • SearchProtocolHost.exe (PID: 1828)
      • SearchProtocolHost.exe (PID: 2736)
    • Changes settings of System certificates

      • FaucetCollector.exe (PID: 2864)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3276)
    • Adds / modifies Windows certificates

      • FaucetCollector.exe (PID: 2864)
    • Creates files in the user directory

      • FaucetCollector.exe (PID: 2864)
    • Reads Environment values

      • FaucetCollector.exe (PID: 2864)
    • Reads Internet Cache Settings

      • FaucetCollector.exe (PID: 2864)
    • Reads internet explorer settings

      • FaucetCollector.exe (PID: 2864)
    • Changes IE settings (feature browser emulation)

      • FaucetCollector.exe (PID: 2864)
    • Starts Internet Explorer

      • FaucetCollector.exe (PID: 2864)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • WinRAR.exe (PID: 3276)
    • Reads settings of System Certificates

      • FaucetCollector.exe (PID: 2864)
    • Application launched itself

      • iexplore.exe (PID: 3524)
    • Changes internet zones settings

      • iexplore.exe (PID: 3524)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2018:06:11 07:16:15
ZipCRC: 0x7e8fcbf6
ZipCompressedSize: 126953
ZipUncompressedSize: 388096
ZipFileName: FaucetCollector v2.1.2 cracked/AutoUpdater.NET.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
6
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs faucetcollector.exe searchprotocolhost.exe no specs iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
1828"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2736"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe7_ Global\UsGthrCtrlFltPipeMssGthrPipe7 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2864"C:\Users\admin\Desktop\FaucetCollector v2.1.2 cracked\FaucetCollector.exe" C:\Users\admin\Desktop\FaucetCollector v2.1.2 cracked\FaucetCollector.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
FaucetCollector
Exit code:
0
Version:
2.0.12.0
Modules
Images
c:\users\admin\desktop\faucetcollector v2.1.2 cracked\faucetcollector.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3276"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\FaucetCollector v2.1.2 cracked.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3524"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
FaucetCollector.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3908"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3524 CREDAT:79873C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
1 678
Read events
1 557
Write events
119
Delete events
2

Modification events

(PID) Process:(3276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3276) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\FaucetCollector v2.1.2 cracked.zip
(PID) Process:(3276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1828) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1828) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:@C:\Windows\System32\ieframe.dll,-912
Value:
HTML Document
Executable files
17
Suspicious files
0
Text files
25
Unknown types
3

Dropped files

PID
Process
Filename
Type
3276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3276.7896\FaucetCollector v2.1.2 cracked\log.txt
MD5:
SHA256:
3276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3276.7896\FaucetCollector v2.1.2 cracked\Cracked by nAV@blackhatsem.com.txttext
MD5:
SHA256:
3276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3276.7896\FaucetCollector v2.1.2 cracked\WebDriver.dll
MD5:
SHA256:
3276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3276.7896\FaucetCollector v2.1.2 cracked\WebDriver.Support.dll
MD5:
SHA256:
3276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3276.7896\FaucetCollector v2.1.2 cracked\x86\liblept172.dll
MD5:
SHA256:
3276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3276.7896\FaucetCollector v2.1.2 cracked\x86\libtesseract304.dll
MD5:
SHA256:
3276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3276.7896\FaucetCollector v2.1.2 cracked\x86\x86\liblept172.dll
MD5:
SHA256:
3276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3276.7896\FaucetCollector v2.1.2 cracked\x86\x86\libtesseract304.dll
MD5:
SHA256:
2864FaucetCollector.exeC:\Users\admin\Desktop\FaucetCollector v2.1.2 cracked\log.txt
MD5:
SHA256:
3276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3276.7896\FaucetCollector v2.1.2 cracked\FaucetCollector.txttext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
11
DNS requests
8
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3524
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2864
FaucetCollector.exe
23.96.103.159:443
faucetcollector.azurewebsites.net
Microsoft Corporation
US
whitelisted
2864
FaucetCollector.exe
152.199.19.160:443
az416426.vo.msecnd.net
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2864
FaucetCollector.exe
40.71.12.231:443
dc.services.visualstudio.com
Microsoft Corporation
US
unknown
2864
FaucetCollector.exe
172.217.168.46:443
www.google-analytics.com
Google Inc.
US
whitelisted
3908
iexplore.exe
13.107.246.10:443
faucetcollector.azureedge.net
Microsoft Corporation
US
whitelisted
2864
FaucetCollector.exe
23.111.8.154:443
oss.maxcdn.com
netDNA
US
unknown
3524
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted

DNS requests

Domain
IP
Reputation
faucetcollector.azurewebsites.net
  • 23.96.103.159
suspicious
oss.maxcdn.com
  • 23.111.8.154
whitelisted
www.google-analytics.com
  • 172.217.168.46
whitelisted
az416426.vo.msecnd.net
  • 152.199.19.160
whitelisted
dc.services.visualstudio.com
  • 40.71.12.231
whitelisted
faucetcollector.azureedge.net
  • 13.107.246.10
malicious
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted

Threats

No threats detected
No debug info