File name:

Gather Proxy 9.0 Premium.rar

Full analysis: https://app.any.run/tasks/2fb0e389-8f16-4a89-9b11-a255e10d175d
Verdict: Malicious activity
Analysis date: June 16, 2019, 13:40:52
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

8708157FE0691BDA48AEADA429D4DABE

SHA1:

44125CC1DA2211521A5036F4D4F2F886DE08F905

SHA256:

AC0D5355CBC7B4586D0435D00F4825430330E8EC55B83D79C6A2A25979AB3AF0

SSDEEP:

98304:rWR737uW6k3gjpIxZJBp72rWZR7YSRUXazL:Sxi43PJBp7WYR7YSy0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Gather Proxy.exe (PID: 2596)
    • Loads dropped or rewritten executable

      • Gather Proxy.exe (PID: 2596)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3136)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • WinRAR.exe (PID: 3136)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
33
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start winrar.exe gather proxy.exe

Process information

PID
CMD
Path
Indicators
Parent process
2596"C:\Users\admin\AppData\Local\Temp\Rar$EXa3136.49376\Gather Proxy 9.0 Premium\Gather Proxy.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3136.49376\Gather Proxy 9.0 Premium\Gather Proxy.exe
WinRAR.exe
User:
admin
Company:
GatherProxy.com
Integrity Level:
MEDIUM
Description:
Gather Proxy 9.0 - Free Pro Proxy and Socks Scraper
Exit code:
0
Version:
9.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3136.49376\gather proxy 9.0 premium\gather proxy.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3136"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Gather Proxy 9.0 Premium.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
477
Read events
465
Write events
12
Delete events
0

Modification events

(PID) Process:(3136) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3136) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3136) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3136) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Gather Proxy 9.0 Premium.rar
(PID) Process:(3136) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3136) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3136) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3136) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3136) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3136) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
11
Suspicious files
0
Text files
10
Unknown types
1

Dropped files

PID
Process
Filename
Type
3136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3136.49376\Gather Proxy 9.0 Premium\Data\configs.gptext
MD5:
SHA256:
3136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3136.49376\Gather Proxy 9.0 Premium\FacebookAPIClass.dllexecutable
MD5:
SHA256:
3136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3136.49376\Gather Proxy 9.0 Premium\Data\country.txttext
MD5:F349544550AB3FA73C515A02B1E28A46
SHA256:3E1DF9E1B2BCDD9223B8092D216F22472685788255441144F935795193454E24
3136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3136.49376\Gather Proxy 9.0 Premium\Data\geo.mmdbmpg
MD5:B3AD53256708B3A42E223F506A7792FF
SHA256:E3B77E008345EDE8AF053FD660B915BEF1D1D956BD34921935A0C08FFF4837B8
3136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3136.49376\Gather Proxy 9.0 Premium\Data\cvtext
MD5:E1DFFC8709F31A4987C8A88334107E89
SHA256:DEAE2D4D75857C1081F113BCFC950DCA567DD5A2E14E6AC8FB8E5785FF4DD5EC
3136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3136.49376\Gather Proxy 9.0 Premium\Data\referrals.txttext
MD5:B5CE4C46FD94C0F038FB7E04B1EF6666
SHA256:04983579DE0B2559D6E55E6447AB60FA1AC97A8DE7FC91B79899DB496571736F
3136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3136.49376\Gather Proxy 9.0 Premium\Data\planetlab.txttext
MD5:4AA755C53F5741125462955E02440DD1
SHA256:B26C86587F82AE186D1860BD03F71858C74F2E1DBA624E7FF85A9DE67FE80D56
3136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3136.49376\Gather Proxy 9.0 Premium\Data\ref.reftext
MD5:EDF1E41F9FE226BE3E61845B747A2C6E
SHA256:C78BA0953491DCCBD7EE2B03CF6AE3A295676715D524B278345FBB31245FBCD5
3136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3136.49376\Gather Proxy 9.0 Premium\Data\agents.txttext
MD5:8520DC38FF84C55CEFA74D492D271DA4
SHA256:FC73F46883AECB0AC9C944A2756CA2CF1AC0E60F963D92700C0DD62EADC3D72B
3136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3136.49376\Gather Proxy 9.0 Premium\symbols.maptext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2596
Gather Proxy.exe
GET
200
97.74.233.74:80
http://update.snaware.com/auth/?k=R8Vq4kkYaooa0Iqshk%2betBU2qIZYMupMml3vsaGJ310JktNnTkcxcuFxUn8KmfOUqkXLbevh5O42UwKTFNJ9pGw8dwWbo3%2f9YXGaXTcGqGayeJ4qQn8tR1%2bz1Yw1%2bm%2fgpGKFpWEA%2fBjkb8PmS5umIY8P4%2b%2b9bppwK50RmJpNGRWSlAWbm4ioPD5PtOQypLxQ
US
text
1.31 Kb
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2596
Gather Proxy.exe
97.74.233.74:80
update.snaware.com
GoDaddy.com, LLC
US
unknown

DNS requests

Domain
IP
Reputation
update.snaware.com
  • 97.74.233.74
malicious

Threats

No threats detected
No debug info