File name:

1.zip

Full analysis: https://app.any.run/tasks/0d3104ce-5b9a-4e43-9553-4b228cf7e38c
Verdict: Malicious activity
Analysis date: August 25, 2019, 16:36:37
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

C1896790BEAC6F61E6D3763D2D7BC72F

SHA1:

90B48A2CF5EEA85314FAA9982A5F085D44DCCCA0

SHA256:

B2E4BC57D61A8DBCB66CBBC44152280EACA0A19DFE3553B82AE99EA6FA175B8B

SSDEEP:

98304:dW3s2v3CCIN/WzRiUePXqnBTbZl68q+iwhwwwDuZLPJpmoLlMOrNC:A3xIi8PABTbZl68Njwww6Zz28NC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Gather Proxy.exe (PID: 3500)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3160)
  • INFO

    • Manual execution by user

      • Gather Proxy.exe (PID: 3500)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (36.3)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0808
ZipCompression: None
ZipModifyDate: 2011:06:11 00:58:26
ZipCRC: 0x4623cd62
ZipCompressedSize: 773968
ZipUncompressedSize: 773968
ZipFileName: Gather Proxy 9.0/msvcr100.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe gather proxy.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3160"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\1.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3500"C:\Users\admin\Desktop\Gather Proxy 9.0\Gather Proxy.exe" C:\Users\admin\Desktop\Gather Proxy 9.0\Gather Proxy.exeexplorer.exe
User:
admin
Company:
GatherProxy.com
Integrity Level:
MEDIUM
Description:
Gather Proxy 9.0 - Free Pro Proxy and Socks Scraper
Exit code:
0
Version:
9.0.0.0
Modules
Images
c:\users\admin\desktop\gather proxy 9.0\gather proxy.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
445
Read events
437
Write events
8
Delete events
0

Modification events

(PID) Process:(3160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3160) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\1.zip
(PID) Process:(3160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
12
Suspicious files
0
Text files
8
Unknown types
1

Dropped files

PID
Process
Filename
Type
3160WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3160.7533\Gather Proxy 9.0\Gather Proxy.exeexecutable
MD5:
SHA256:
3160WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3160.7533\Gather Proxy 9.0\FacebookAPIClass.dllexecutable
MD5:
SHA256:
3160WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3160.7533\Gather Proxy 9.0\Data\configs.gptext
MD5:
SHA256:
3160WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3160.7533\Gather Proxy 9.0\msvcp100.dllexecutable
MD5:BC83108B18756547013ED443B8CDB31B
SHA256:B2AD109C15EAA92079582787B7772BA0A2F034F7D075907FF87028DF0EAEA671
3160WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3160.7533\Gather Proxy 9.0\Noesis.Javascript.dllexecutable
MD5:363F567FE571B4BD278E5D604EF7EE2C
SHA256:58B8362E5F34F4F24495F947550FFFB1D528FA89A4E06D4958EB287A514440CD
3160WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3160.7533\Gather Proxy 9.0\Newtonsoft.Json.dllexecutable
MD5:5E02DDAF3B02E43E532FC6A52B04D14B
SHA256:78BEDD9FCE877A71A8D8FF9A813662D8248361E46705C4EF7AFC61D440FF2EEB
3160WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3160.7533\Gather Proxy 9.0\RestSharp.dllexecutable
MD5:07187F3DD0263CDCABA9C800444379A5
SHA256:317690CB0B82E5632E132AA384843729CD31E24CCC4B1FA00BA8157CB8D82F7E
3160WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3160.7533\Gather Proxy 9.0\MaxMind.GeoIP2.dllexecutable
MD5:D4B9A139CF8E834D45F1AD756C786921
SHA256:393E6AFC7EB0E019319EEE43BAFEEBE76625DA5999FD78E4EBF07DF9F0AD8AEE
3160WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3160.7533\Gather Proxy 9.0\HtmlAgilityPack.dllexecutable
MD5:B768306987227D31BF07277C1AE65A57
SHA256:DB48B1FEA16C5DA3B80CBDE4D351D614957240CA70213FA82B6A7535B02AAF28
3160WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3160.7533\Gather Proxy 9.0\msvcr100.dllexecutable
MD5:0E37FBFA79D349D672456923EC5FBBE3
SHA256:8793353461826FBD48F25EA8B835BE204B758CE7510DB2AF631B28850355BD18
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info