File name: | psiphon 3.181.rar |
Full analysis: | https://app.any.run/tasks/2b7f695b-affc-488b-862a-09c876e64f65 |
Verdict: | Malicious activity |
Analysis date: | December 17, 2023, 20:03:44 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-rar |
File info: | RAR archive data, v5 |
MD5: | 1996B28F607AB7E073D52162DEAB7290 |
SHA1: | 62A1EA85CBC44ED805430B87098E126BBD681268 |
SHA256: | BAAF2BA039711FD4CF32B04BD815306C0219AA49E8747C54D83F2EB2F56F811F |
SSDEEP: | 98304:/JcRhgmwp1Rmy8uJBx836wr5emtD6FDLwu/Kak+5tm27L8BnGV85ggjCNzfVwWqJ:sy3bVOMw+U |
.rar | | | RAR compressed archive (v5.0) (61.5) |
---|---|---|
.rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
128 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\psiphon 3.181.rar" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
884 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2284 --field-trial-handle=1276,i,4725223737852863716,13046411613256394610,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
1196 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1604 --field-trial-handle=1276,i,4725223737852863716,13046411613256394610,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
1572 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate https://ipfounder.net/?sponsor_id=1BC527D3D09985CF&sponsor=psiphon&client_region=DE&client_asn=174&client_platform=windows&secret=580EfjEI29xL3hoyU6dgP4vSEVxdcGI7JDFkxgjds7PHulSEF0wmORpvzbqxyTwYtpowsY4xMFnfWEnTghe6l8jiV9K5QSZoir2i6fDeKJD6EhL6DkoYTEMu2EE9YJvy3LdCUZ7ncdVC6ipgWx06wznvDLbY1ajfcfRGCpfsQJei2q6tb0GSFh1QK3x3qXKwyjmNPc5J&psireason=connect&psicash=eyJtZXRhZGF0YSI6eyJjbGllbnRfcmVnaW9uIjoiREUiLCJjbGllbnRfdmVyc2lvbiI6IjE4MSIsInByb3BhZ2F0aW9uX2NoYW5uZWxfaWQiOiI5MkFBQ0M1QkFCRTA5NDRDIiwic3BvbnNvcl9pZCI6IjFCQzUyN0QzRDA5OTg1Q0YiLCJ1c2VyX2FnZW50IjoiUHNpcGhvbi1Qc2lDYXNoLVdpbmRvd3MiLCJ2IjoxfSwidGltZXN0YW1wIjoiMjAyMy0xMi0xN1QyMDowNDoyNC42ODlaIiwidG9rZW5zIjpudWxsLCJ2IjoxfQ | C:\Program Files\Microsoft\Edge\Application\msedge.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
1772 | "C:\Users\admin\Desktop\psiphon3.exe" | C:\Users\admin\Desktop\psiphon3.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
2092 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4104 --field-trial-handle=1276,i,4725223737852863716,13046411613256394610,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
2260 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xf0,0x6a8cf598,0x6a8cf5a8,0x6a8cf5b4 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
2344 | C:\Users\admin\AppData\Local\Temp\psiphon-tunnel-core.exe --config "C:\Users\admin\AppData\Local\Psiphon3\psiphon.config" --serverList "C:\Users\admin\AppData\Local\Psiphon3\server_list.dat" | C:\Users\admin\AppData\Local\Temp\psiphon-tunnel-core.exe | psiphon3.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
2404 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1428 --field-trial-handle=1384,i,7638341578663324424,12578805262607824497,131072 /prefetch:3 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
2440 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://ipfounder.net/?sponsor_id=1BC527D3D09985CF&sponsor=psiphon&client_region=DE&client_asn=174&client_platform=windows&secret=580EfjEI29xL3hoyU6dgP4vSEVxdcGI7JDFkxgjds7PHulSEF0wmORpvzbqxyTwYtpowsY4xMFnfWEnTghe6l8jiV9K5QSZoir2i6fDeKJD6EhL6DkoYTEMu2EE9YJvy3LdCUZ7ncdVC6ipgWx06wznvDLbY1ajfcfRGCpfsQJei2q6tb0GSFh1QK3x3qXKwyjmNPc5J&psireason=connect&psicash=eyJtZXRhZGF0YSI6eyJjbGllbnRfcmVnaW9uIjoiREUiLCJjbGllbnRfdmVyc2lvbiI6IjE4MSIsInByb3BhZ2F0aW9uX2NoYW5uZWxfaWQiOiI5MkFBQ0M1QkFCRTA5NDRDIiwic3BvbnNvcl9pZCI6IjFCQzUyN0QzRDA5OTg1Q0YiLCJ1c2VyX2FnZW50IjoiUHNpcGhvbi1Qc2lDYXNoLVdpbmRvd3MiLCJ2IjoxfSwidGltZXN0YW1wIjoiMjAyMy0xMi0xN1QyMDowNDoyNC42ODlaIiwidG9rZW5zIjpudWxsLCJ2IjoxfQ | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | psiphon3.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
|
(PID) Process: | (128) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
(PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
(PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
(PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
(PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2440 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Local State | binary | |
MD5:610C9F2362B4149F301D47323F9ACEB3 | SHA256:FC8CD0369F4A8EB04EF28FF9061C1F90B9FD46FFAB7A3FD81A76EA050A6E648D | |||
1772 | psiphon3.exe | C:\Users\admin\AppData\Local\Psiphon3\psicash\psicashdatastore.prod.commit | binary | |
MD5:5AD5CC4D26869082EFD29C436B57384A | SHA256:C5C24F7CA1C946FA4DFD44407409C8E11EC6E41F0E1C7C45BF8381B42AFB31F1 | |||
1772 | psiphon3.exe | C:\Users\admin\AppData\Local\Psiphon3\psicash\psicashdatastore.prod | binary | |
MD5:5AD5CC4D26869082EFD29C436B57384A | SHA256:C5C24F7CA1C946FA4DFD44407409C8E11EC6E41F0E1C7C45BF8381B42AFB31F1 | |||
2440 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Local State~RFe66b4.TMP | binary | |
MD5:3B724992C6EFD0987FCBB5A9465F7072 | SHA256:E1E95234896410D16CA9EB13B7AF08A004FB231307E17D619C7015A3DACD889A | |||
2260 | msedge.exe | — | ||
MD5:— | SHA256:— | |||
1572 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RFe68d7.TMP | — | |
MD5:— | SHA256:— | |||
1572 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
1772 | psiphon3.exe | C:\Users\admin\AppData\Local\Psiphon3\server_list.dat | text | |
MD5:40485BF9D2EB453C7AF730516FFD04F2 | SHA256:B6DD7C80133BD19B64C6DB667A9287B91F5E5C7747969A44B648F3898DAD187F | |||
1772 | psiphon3.exe | C:\Users\admin\AppData\Local\Psiphon3\psicash\psicashdatastore.prod.temp | binary | |
MD5:5AD5CC4D26869082EFD29C436B57384A | SHA256:C5C24F7CA1C946FA4DFD44407409C8E11EC6E41F0E1C7C45BF8381B42AFB31F1 | |||
1772 | psiphon3.exe | C:\Users\admin\AppData\Local\Temp\psiphon-tunnel-core.exe | executable | |
MD5:D7C2D14B93FC402F1183F9D80753FC64 | SHA256:9C3476592811314C8FFDEA29DB94E1F15F4F31774DB21EDC5AA5573586CD8117 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2344 | psiphon-tunnel-core.exe | POST | — | 138.199.37.231:80 | http://www.discoverydarkflight.com/ | unknown | — | — | — |
2344 | psiphon-tunnel-core.exe | POST | 200 | 146.70.182.211:80 | http://www.gymdatecan.net/ | unknown | binary | 520 b | — |
2344 | psiphon-tunnel-core.exe | POST | 200 | 146.70.182.211:80 | http://www.gymdatecan.net/ | unknown | binary | 6.46 Kb | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2344 | psiphon-tunnel-core.exe | 138.199.37.231:443 | b-cdn.net | Datacamp Limited | DE | unknown |
2344 | psiphon-tunnel-core.exe | 74.208.176.234:53 | — | — | — | unknown |
2344 | psiphon-tunnel-core.exe | 77.68.55.168:53 | — | IONOS SE | GB | unknown |
2344 | psiphon-tunnel-core.exe | 5.254.18.141:53 | — | — | — | unknown |
2344 | psiphon-tunnel-core.exe | 5.157.42.6:554 | — | Orion Network Limited | NL | unknown |
2344 | psiphon-tunnel-core.exe | 5.254.60.82:554 | — | Voxility LLP | GB | unknown |
2344 | psiphon-tunnel-core.exe | 77.68.81.181:53 | — | IONOS SE | GB | unknown |
Domain | IP | Reputation |
---|---|---|
b-cdn.net |
| unknown |
PID | Process | Class | Message |
---|---|---|---|
— | — | Potential Corporate Privacy Violation | ET DNS Non-DNS or Non-Compliant DNS traffic on DNS port Opcode 8 through 15 set |
— | — | Potential Corporate Privacy Violation | ET DNS Non-DNS or Non-Compliant DNS traffic on DNS port Opcode 6 or 7 set |
— | — | A Network Trojan was detected | AV POLICY Suspicious Image File Upload over HTTP |
Process | Message |
---|---|
psiphon3.exe | |
psiphon3.exe | Client Version: 181 |
psiphon3.exe | 2023-12-17T20:04:22.768Z: |
psiphon3.exe | Psiphon Tunnel connecting... |
psiphon3.exe | 2023-12-17T20:04:22.815Z: |
psiphon3.exe | |
psiphon3.exe | |
psiphon3.exe | {"data":{"data":{"message":"RemoteServerListURLs overridden by AdditionalParameters"},"noticeType":"Info","timestamp":"2023-12-17T20:04:23.213Z"},"msg":"CoreNotice","timestamp!!timestamp":"2023-12-17T20:04:23.246Z"}
|
psiphon3.exe | {"data":{"data":{"message":"FeedbackUploadURLs overridden by AdditionalParameters"},"noticeType":"Info","timestamp":"2023-12-17T20:04:23.213Z"},"msg":"CoreNotice","timestamp!!timestamp":"2023-12-17T20:04:23.246Z"}
|
psiphon3.exe | |