analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

1.zip

Full analysis: https://app.any.run/tasks/5207ff5a-1773-44dd-9198-b7be8747c70f
Verdict: Malicious activity
Analysis date: August 25, 2019, 11:30:51
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

C1896790BEAC6F61E6D3763D2D7BC72F

SHA1:

90B48A2CF5EEA85314FAA9982A5F085D44DCCCA0

SHA256:

B2E4BC57D61A8DBCB66CBBC44152280EACA0A19DFE3553B82AE99EA6FA175B8B

SSDEEP:

98304:dW3s2v3CCIN/WzRiUePXqnBTbZl68q+iwhwwwDuZLPJpmoLlMOrNC:A3xIi8PABTbZl68Njwww6Zz28NC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • Gather Proxy.exe (PID: 2848)
      • SearchProtocolHost.exe (PID: 1512)
    • Application was dropped or rewritten from another process

      • Gather Proxy.exe (PID: 2848)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3724)
  • INFO

    • Manual execution by user

      • Gather Proxy.exe (PID: 2848)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (36.3)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0808
ZipCompression: None
ZipModifyDate: 2011:06:11 00:58:26
ZipCRC: 0x4623cd62
ZipCompressedSize: 773968
ZipUncompressedSize: 773968
ZipFileName: Gather Proxy 9.0/msvcr100.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe gather proxy.exe searchprotocolhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3724"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\1.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
2848"C:\Users\admin\Desktop\Gather Proxy 9.0\Gather Proxy.exe" C:\Users\admin\Desktop\Gather Proxy 9.0\Gather Proxy.exe
explorer.exe
User:
admin
Company:
GatherProxy.com
Integrity Level:
MEDIUM
Description:
Gather Proxy 9.0 - Free Pro Proxy and Socks Scraper
Exit code:
0
Version:
9.0.0.0
1512"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Total events
823
Read events
802
Write events
0
Delete events
0

Modification events

No data
Executable files
12
Suspicious files
0
Text files
9
Unknown types
1

Dropped files

PID
Process
Filename
Type
3724WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3724.19353\Gather Proxy 9.0\Data\configs.gptext
MD5:721026B91E26C02E975FF412FAFE2E22
SHA256:B8A1440118FE421D1A65F5E8E1735B954FA4C7B597C71F4CC0B50F8B50F5FA66
3724WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3724.19353\Gather Proxy 9.0\Gather Proxy.exeexecutable
MD5:EBC8351C3C63B359288FB526C093DA70
SHA256:1E348A4C1C708F33792FB68D6BE5B8B983D02BE249453B8FC1C7878A3BA98F60
3724WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3724.19353\Gather Proxy 9.0\FacebookAPIClass11.dllexecutable
MD5:79BE98B2E5033DFD39467E60B4E3F11D
SHA256:0A2E8EAED3D160444512E0D9FD45FE1287308D30BF29891B0DB9AF3E25485FD8
3724WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3724.19353\Gather Proxy 9.0\FacebookAPIClass.dllexecutable
MD5:D4B980E76FBFCDA00A08A73C3C5CF3E6
SHA256:9DD7A4C9BAA2695C3AFA86917F3946BB2D69F2562C7AF37FE160673A4B055832
3724WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3724.19353\Gather Proxy 9.0\Gather Proxy.exe.configxml
MD5:365E8A1FAE1391145F187F048680FC08
SHA256:40A15F3B0184FB80CC36F771B589D2338CDA22EBC2F0EF0711E0C69B4DBCE4CC
3724WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3724.19353\Gather Proxy 9.0\msvcp100.dllexecutable
MD5:BC83108B18756547013ED443B8CDB31B
SHA256:B2AD109C15EAA92079582787B7772BA0A2F034F7D075907FF87028DF0EAEA671
3724WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3724.19353\Gather Proxy 9.0\HtmlAgilityPack.dllexecutable
MD5:B768306987227D31BF07277C1AE65A57
SHA256:DB48B1FEA16C5DA3B80CBDE4D351D614957240CA70213FA82B6A7535B02AAF28
3724WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3724.19353\Gather Proxy 9.0\RestSharp.dllexecutable
MD5:07187F3DD0263CDCABA9C800444379A5
SHA256:317690CB0B82E5632E132AA384843729CD31E24CCC4B1FA00BA8157CB8D82F7E
3724WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3724.19353\Gather Proxy 9.0\Data\agents.txttext
MD5:8520DC38FF84C55CEFA74D492D271DA4
SHA256:FC73F46883AECB0AC9C944A2756CA2CF1AC0E60F963D92700C0DD62EADC3D72B
3724WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3724.19353\Gather Proxy 9.0\MaxMind.Db.dllexecutable
MD5:4D1FC03277F904C3172A4C23ED36B032
SHA256:68540771C4099BAB7A26AB31F59F92E12182B9050D84E625BE7BD5778871F475
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2848
Gather Proxy.exe
GET
200
97.74.233.74:80
http://update.snaware.com/auth/?k=J2V0fjtxBqT5SnvBmMH0InodFEECKLj9f2UujyKWTbMWnkWh1Ehyx%2bZcMiwbtI%2bH4vzA2j9IUi%2bVfyx%2by0ikMoi6GZG4dZgMB8SfXcO4kRK0aW7vAElhV3li5YpPyh9Qf4kpo4FTzosPvdFD%2b6coJyTVngZbWxloaAvNc13svYdQq7Af8QjWaYgNOsdFBNO3
US
text
1.31 Kb
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2848
Gather Proxy.exe
97.74.233.74:80
update.snaware.com
GoDaddy.com, LLC
US
unknown

DNS requests

Domain
IP
Reputation
update.snaware.com
  • 97.74.233.74
malicious

Threats

No threats detected
No debug info