analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

1.zip

Full analysis: https://app.any.run/tasks/0d3104ce-5b9a-4e43-9553-4b228cf7e38c
Verdict: Malicious activity
Analysis date: August 25, 2019, 16:36:37
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

C1896790BEAC6F61E6D3763D2D7BC72F

SHA1:

90B48A2CF5EEA85314FAA9982A5F085D44DCCCA0

SHA256:

B2E4BC57D61A8DBCB66CBBC44152280EACA0A19DFE3553B82AE99EA6FA175B8B

SSDEEP:

98304:dW3s2v3CCIN/WzRiUePXqnBTbZl68q+iwhwwwDuZLPJpmoLlMOrNC:A3xIi8PABTbZl68Njwww6Zz28NC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Gather Proxy.exe (PID: 3500)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3160)
  • INFO

    • Manual execution by user

      • Gather Proxy.exe (PID: 3500)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (36.3)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0808
ZipCompression: None
ZipModifyDate: 2011:06:11 00:58:26
ZipCRC: 0x4623cd62
ZipCompressedSize: 773968
ZipUncompressedSize: 773968
ZipFileName: Gather Proxy 9.0/msvcr100.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe gather proxy.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3160"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\1.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
3500"C:\Users\admin\Desktop\Gather Proxy 9.0\Gather Proxy.exe" C:\Users\admin\Desktop\Gather Proxy 9.0\Gather Proxy.exeexplorer.exe
User:
admin
Company:
GatherProxy.com
Integrity Level:
MEDIUM
Description:
Gather Proxy 9.0 - Free Pro Proxy and Socks Scraper
Version:
9.0.0.0
Total events
445
Read events
437
Write events
8
Delete events
0

Modification events

(PID) Process:(3160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3160) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\1.zip
(PID) Process:(3160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
12
Suspicious files
0
Text files
8
Unknown types
1

Dropped files

PID
Process
Filename
Type
3160WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3160.7533\Gather Proxy 9.0\Gather Proxy.exeexecutable
MD5:EBC8351C3C63B359288FB526C093DA70
SHA256:1E348A4C1C708F33792FB68D6BE5B8B983D02BE249453B8FC1C7878A3BA98F60
3160WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3160.7533\Gather Proxy 9.0\FacebookAPIClass11.dllexecutable
MD5:79BE98B2E5033DFD39467E60B4E3F11D
SHA256:0A2E8EAED3D160444512E0D9FD45FE1287308D30BF29891B0DB9AF3E25485FD8
3160WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3160.7533\Gather Proxy 9.0\FacebookAPIClass.dllexecutable
MD5:D4B980E76FBFCDA00A08A73C3C5CF3E6
SHA256:9DD7A4C9BAA2695C3AFA86917F3946BB2D69F2562C7AF37FE160673A4B055832
3160WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3160.7533\Gather Proxy 9.0\Data\referrals.txttext
MD5:B5CE4C46FD94C0F038FB7E04B1EF6666
SHA256:04983579DE0B2559D6E55E6447AB60FA1AC97A8DE7FC91B79899DB496571736F
3160WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3160.7533\Gather Proxy 9.0\GC.dllexecutable
MD5:BEA3694CC7C60877D1B3C07DE352ADAB
SHA256:CEDB323B29D5C3104EB42D39E93AECC5CC3A69D2BA507F732F176A7051ECBCC3
3160WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3160.7533\Gather Proxy 9.0\HtmlAgilityPack.dllexecutable
MD5:B768306987227D31BF07277C1AE65A57
SHA256:DB48B1FEA16C5DA3B80CBDE4D351D614957240CA70213FA82B6A7535B02AAF28
3160WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3160.7533\Gather Proxy 9.0\MaxMind.GeoIP2.dllexecutable
MD5:D4B9A139CF8E834D45F1AD756C786921
SHA256:393E6AFC7EB0E019319EEE43BAFEEBE76625DA5999FD78E4EBF07DF9F0AD8AEE
3160WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3160.7533\Gather Proxy 9.0\Data\ref.reftext
MD5:EDF1E41F9FE226BE3E61845B747A2C6E
SHA256:C78BA0953491DCCBD7EE2B03CF6AE3A295676715D524B278345FBB31245FBCD5
3160WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3160.7533\Gather Proxy 9.0\Data\configs.gptext
MD5:721026B91E26C02E975FF412FAFE2E22
SHA256:B8A1440118FE421D1A65F5E8E1735B954FA4C7B597C71F4CC0B50F8B50F5FA66
3160WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3160.7533\Gather Proxy 9.0\msvcp100.dllexecutable
MD5:BC83108B18756547013ED443B8CDB31B
SHA256:B2AD109C15EAA92079582787B7772BA0A2F034F7D075907FF87028DF0EAEA671
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info