File name:

MinerSearch_v1.4.7.4.rar

Full analysis: https://app.any.run/tasks/3aa2699b-772e-4a0d-8052-d61ff8bc3c8d
Verdict: Malicious activity
Analysis date: September 16, 2024, 12:12:25
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

568EA060DBB22BE53C892F3E24E95763

SHA1:

FB1FD06236AD7531D23735ADE22CC05447E9D348

SHA256:

B94BA59ECD09A48C43E7B6ED52C0AA5121E4DE8AF0411D52FAF43BDD5A4788C7

SSDEEP:

98304:6Lq9TOdDOfal+wVgY2zqbYBrGH0yHRbt53yxex5T9qsd+iiT1SviJpkQJPoS7NDD:jxGuMHFNYETtug6E7c

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • MinerSearch_v1.4.7.4.exe (PID: 2636)
    • The process verifies whether the antivirus software is installed

      • MinerSearch_v1.4.7.4.exe (PID: 2636)
    • Adds/modifies Windows certificates

      • MinerSearch_v1.4.7.4.exe (PID: 2636)
    • Checks Windows Trust Settings

      • MinerSearch_v1.4.7.4.exe (PID: 2636)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6812)
    • Manual execution by a user

      • Helper.exe (PID: 1616)
      • Helper.exe (PID: 2228)
      • MinerSearch_v1.4.7.4.exe (PID: 6888)
      • MinerSearch_v1.4.7.4.exe (PID: 2636)
      • MinerSearch_v1.4.7.4.exe (PID: 6792)
      • Helper.exe (PID: 6412)
      • MinerSearch_v1.4.7.4.exe (PID: 4024)
      • MinerSearch_v1.4.7.4.exe (PID: 7060)
      • MinerSearch_v1.4.7.4.exe (PID: 1936)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 6812)
    • Reads mouse settings

      • Helper.exe (PID: 1616)
      • Helper.exe (PID: 2228)
    • Checks supported languages

      • MinerSearch_v1.4.7.4.exe (PID: 2636)
      • Helper.exe (PID: 1616)
      • Helper.exe (PID: 2228)
    • Reads the machine GUID from the registry

      • MinerSearch_v1.4.7.4.exe (PID: 2636)
    • Checks proxy server information

      • MinerSearch_v1.4.7.4.exe (PID: 2636)
    • Reads the computer name

      • MinerSearch_v1.4.7.4.exe (PID: 2636)
    • Creates files or folders in the user directory

      • MinerSearch_v1.4.7.4.exe (PID: 2636)
    • Reads the software policy settings

      • MinerSearch_v1.4.7.4.exe (PID: 2636)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
148
Monitored processes
14
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs helper.exe no specs helper.exe minersearch_v1.4.7.4.exe no specs minersearch_v1.4.7.4.exe conhost.exe no specs minersearch_v1.4.7.4.exe no specs minersearch_v1.4.7.4.exe conhost.exe no specs minersearch_v1.4.7.4.exe no specs minersearch_v1.4.7.4.exe conhost.exe no specs helper.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
884\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeMinerSearch_v1.4.7.4.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
1616"C:\Users\admin\Desktop\MinerSearch_v1.4.7.4\Helper.exe" C:\Users\admin\Desktop\MinerSearch_v1.4.7.4\Helper.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\minersearch_v1.4.7.4\helper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
1936"C:\Users\admin\Desktop\MinerSearch_v1.4.7.4\MinerSearch_v1.4.7.4.exe" "C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Helper.exe"C:\Users\admin\Desktop\MinerSearch_v1.4.7.4\MinerSearch_v1.4.7.4.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
1.4.7.4
2228"C:\Users\admin\Desktop\MinerSearch_v1.4.7.4\Helper.exe" C:\Users\admin\Desktop\MinerSearch_v1.4.7.4\Helper.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\minersearch_v1.4.7.4\helper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\gdi32.dll
2636"C:\Users\admin\Desktop\MinerSearch_v1.4.7.4\MinerSearch_v1.4.7.4.exe" C:\Users\admin\Desktop\MinerSearch_v1.4.7.4\MinerSearch_v1.4.7.4.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
3221225786
Version:
1.4.7.4
Modules
Images
c:\users\admin\desktop\minersearch_v1.4.7.4\minersearch_v1.4.7.4.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
4024"C:\Users\admin\Desktop\MinerSearch_v1.4.7.4\MinerSearch_v1.4.7.4.exe" C:\Users\admin\Desktop\MinerSearch_v1.4.7.4\MinerSearch_v1.4.7.4.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
1.4.7.4
5940C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
6412"C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Helper.exe" C:\Users\admin\Desktop\MinerSearch_v1.4.7.4\MinerSearch_v1.4.7.4.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Helper.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
6532\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeMinerSearch_v1.4.7.4.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6748\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeMinerSearch_v1.4.7.4.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Total events
37 293
Read events
37 267
Write events
22
Delete events
4

Modification events

(PID) Process:(6812) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(6812) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\MinerSearch_v1.4.7.4.rar
(PID) Process:(6812) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6812) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6812) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6812) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6812) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(6812) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
(PID) Process:(6812) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6812) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:psize
Value:
80
Executable files
5
Suspicious files
93
Text files
5
Unknown types
6

Dropped files

PID
Process
Filename
Type
6812WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6812.7398\MinerSearch_v1.4.7.4\dbase.dllexecutable
MD5:D3124D4AF1578F451BDA44BB6EE47E03
SHA256:2BB837031E0A50E8F2BF82F1B2FD1DEE66DA1CD2D3BD21AEC5070C2E741293B7
6812WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6812.7398\MinerSearch_v1.4.7.4\Helper.exeexecutable
MD5:CFAC88EABC29939AD8FF9F63D4C83582
SHA256:2A204312D040E59A12F75BB2558A69803F09FAF8CC50E8DBF71467CB728E8904
6812WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6812.7398\MinerSearch_v1.4.7.4\Microsoft.Win32.TaskScheduler.dllexecutable
MD5:0616EA42B68A8F5F2F01BCD985BDCBC7
SHA256:EA27C65491119EEE5C8E87CE3D470783580DB8FC5BD141C496768D7D0CCE779A
6812WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6812.7398\MinerSearch_v1.4.7.4\MinerSearch_v1.4.7.4.exeexecutable
MD5:F7742D76E9EBCD8AEFB330D36F65C28F
SHA256:6D6922F898D93EBD76428E53BC01D0ED314F9D8F9E23A11B9708457C7BC6C15F
6812WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6812.7398\MinerSearch_v1.4.7.4\netlib.dllexecutable
MD5:E1F852BA7AD79847091EF8FF10B83421
SHA256:B7427E4FD74BEEFE74C89B3DB66CDFCF674382DC80802C787E97FED23FD9259E
6812WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6812.7398\MinerSearch_v1.4.7.4\hash.txttext
MD5:0CF3D3E0FBB5AFD2CDCB07BAFEBC692B
SHA256:774094F9B7A937E33D65E75D50D29DB6AF3B6F3BE365236DE3DA2B4415844BEC
2636MinerSearch_v1.4.7.4.exeC:\_MinerSearchLogs\MinerSearch_9_16_2024_12-12-58_PM.logtext
MD5:C36DF70B5D0692A5D37FC9052CB39C23
SHA256:B3F477CE6C434D04D90CF8E0A4EB4DE75E9199C05D784F03A82CF77DD010B6C4
2636MinerSearch_v1.4.7.4.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEBbinary
MD5:E4026E1653312D9C24E00AE06DA330B4
SHA256:DFF8D3F8A77FA0774A13388A8EDB85BD077BBBA56CD06D95CEE31423B00629E0
2636MinerSearch_v1.4.7.4.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141binary
MD5:5F4493E061A5AE0E5D239545532879FD
SHA256:9E567760B93A70DC3E703900CE42064B96B21537D9870CD35D428444AC65B9C7
2636MinerSearch_v1.4.7.4.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0B8A20E1F3F4D73D52A19929F922C892binary
MD5:3866C1B2D23DA378C9CA47B5310DBB23
SHA256:EA9F4C3B28DF7B07CB375BB4BA9D4F4611E6AD5020A7E2FA7B7816EA795A2667
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
62
TCP/UDP connections
63
DNS requests
34
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2036
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6012
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6124
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6124
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2636
MinerSearch_v1.4.7.4.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
whitelisted
2636
MinerSearch_v1.4.7.4.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicWinProPCA2011_2011-10-19.crl
unknown
whitelisted
2636
MinerSearch_v1.4.7.4.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl
unknown
whitelisted
2636
MinerSearch_v1.4.7.4.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEARSlvj82CmnXclClPWkFaQ%3D
unknown
whitelisted
2636
MinerSearch_v1.4.7.4.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTjzY2p9Pa8oibmj%2BNSMWsz63kmWgQUuhbZbU2FL3MpdpovdYxqII%2BeyG8CEAxNaXJLlPo8Kko9KQeAPVo%3D
unknown
whitelisted
2636
MinerSearch_v1.4.7.4.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6012
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6400
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
6012
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6012
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3260
svchost.exe
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2036
svchost.exe
40.126.32.136:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
  • 51.104.136.2
whitelisted
google.com
  • 142.250.184.206
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
login.live.com
  • 40.126.32.136
  • 20.190.160.20
  • 40.126.32.72
  • 20.190.160.17
  • 40.126.32.74
  • 40.126.32.140
  • 40.126.32.76
  • 40.126.32.138
  • 20.190.159.0
  • 20.190.159.71
  • 20.190.159.64
  • 20.190.159.23
  • 20.190.159.73
  • 20.190.159.75
  • 20.190.159.4
  • 40.126.31.73
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
slscr.update.microsoft.com
  • 40.127.169.103
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
crl3.digicert.com
  • 192.229.221.95
whitelisted

Threats

No threats detected
No debug info