File name:

1.zip

Full analysis: https://app.any.run/tasks/5207ff5a-1773-44dd-9198-b7be8747c70f
Verdict: Malicious activity
Analysis date: August 25, 2019, 11:30:51
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

C1896790BEAC6F61E6D3763D2D7BC72F

SHA1:

90B48A2CF5EEA85314FAA9982A5F085D44DCCCA0

SHA256:

B2E4BC57D61A8DBCB66CBBC44152280EACA0A19DFE3553B82AE99EA6FA175B8B

SSDEEP:

98304:dW3s2v3CCIN/WzRiUePXqnBTbZl68q+iwhwwwDuZLPJpmoLlMOrNC:A3xIi8PABTbZl68Njwww6Zz28NC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Gather Proxy.exe (PID: 2848)
    • Loads dropped or rewritten executable

      • Gather Proxy.exe (PID: 2848)
      • SearchProtocolHost.exe (PID: 1512)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3724)
  • INFO

    • Manual execution by user

      • Gather Proxy.exe (PID: 2848)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (36.3)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0808
ZipCompression: None
ZipModifyDate: 2011:06:11 00:58:26
ZipCRC: 0x4623cd62
ZipCompressedSize: 773968
ZipUncompressedSize: 773968
ZipFileName: Gather Proxy 9.0/msvcr100.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe gather proxy.exe searchprotocolhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1512"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2848"C:\Users\admin\Desktop\Gather Proxy 9.0\Gather Proxy.exe" C:\Users\admin\Desktop\Gather Proxy 9.0\Gather Proxy.exe
explorer.exe
User:
admin
Company:
GatherProxy.com
Integrity Level:
MEDIUM
Description:
Gather Proxy 9.0 - Free Pro Proxy and Socks Scraper
Exit code:
0
Version:
9.0.0.0
Modules
Images
c:\users\admin\desktop\gather proxy 9.0\gather proxy.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3724"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\1.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
823
Read events
802
Write events
21
Delete events
0

Modification events

(PID) Process:(3724) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3724) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3724) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3724) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\1.zip
(PID) Process:(3724) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3724) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3724) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3724) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1512) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1512) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
12
Suspicious files
0
Text files
9
Unknown types
1

Dropped files

PID
Process
Filename
Type
3724WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3724.19353\Gather Proxy 9.0\Gather Proxy.exeexecutable
MD5:
SHA256:
3724WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3724.19353\Gather Proxy 9.0\Newtonsoft.Json.dllexecutable
MD5:5E02DDAF3B02E43E532FC6A52B04D14B
SHA256:78BEDD9FCE877A71A8D8FF9A813662D8248361E46705C4EF7AFC61D440FF2EEB
3724WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3724.19353\Gather Proxy 9.0\GC.dllexecutable
MD5:BEA3694CC7C60877D1B3C07DE352ADAB
SHA256:CEDB323B29D5C3104EB42D39E93AECC5CC3A69D2BA507F732F176A7051ECBCC3
3724WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3724.19353\Gather Proxy 9.0\HtmlAgilityPack.dllexecutable
MD5:B768306987227D31BF07277C1AE65A57
SHA256:DB48B1FEA16C5DA3B80CBDE4D351D614957240CA70213FA82B6A7535B02AAF28
3724WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3724.19353\Gather Proxy 9.0\Gather Proxy.exe.configxml
MD5:365E8A1FAE1391145F187F048680FC08
SHA256:40A15F3B0184FB80CC36F771B589D2338CDA22EBC2F0EF0711E0C69B4DBCE4CC
3724WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3724.19353\Gather Proxy 9.0\MaxMind.GeoIP2.dllexecutable
MD5:D4B9A139CF8E834D45F1AD756C786921
SHA256:393E6AFC7EB0E019319EEE43BAFEEBE76625DA5999FD78E4EBF07DF9F0AD8AEE
3724WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3724.19353\Gather Proxy 9.0\Noesis.Javascript.dllexecutable
MD5:363F567FE571B4BD278E5D604EF7EE2C
SHA256:58B8362E5F34F4F24495F947550FFFB1D528FA89A4E06D4958EB287A514440CD
3724WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3724.19353\Gather Proxy 9.0\Data\configs.gptext
MD5:
SHA256:
3724WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3724.19353\Gather Proxy 9.0\FacebookAPIClass.dllexecutable
MD5:
SHA256:
3724WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3724.19353\Gather Proxy 9.0\Data\referrals.txttext
MD5:B5CE4C46FD94C0F038FB7E04B1EF6666
SHA256:04983579DE0B2559D6E55E6447AB60FA1AC97A8DE7FC91B79899DB496571736F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2848
Gather Proxy.exe
GET
200
97.74.233.74:80
http://update.snaware.com/auth/?k=J2V0fjtxBqT5SnvBmMH0InodFEECKLj9f2UujyKWTbMWnkWh1Ehyx%2bZcMiwbtI%2bH4vzA2j9IUi%2bVfyx%2by0ikMoi6GZG4dZgMB8SfXcO4kRK0aW7vAElhV3li5YpPyh9Qf4kpo4FTzosPvdFD%2b6coJyTVngZbWxloaAvNc13svYdQq7Af8QjWaYgNOsdFBNO3
US
text
1.31 Kb
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2848
Gather Proxy.exe
97.74.233.74:80
update.snaware.com
GoDaddy.com, LLC
US
unknown

DNS requests

Domain
IP
Reputation
update.snaware.com
  • 97.74.233.74
malicious

Threats

No threats detected
No debug info