File name:

Youtube View Booster V1.2.zip

Full analysis: https://app.any.run/tasks/f102884e-95a8-4ff9-8495-182753b8ae44
Verdict: Malicious activity
Analysis date: May 09, 2020, 16:23:09
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

E43908C1B77CB6FE6069524C42C8C703

SHA1:

4F2E8B0F6FEEC62A7A81D6961ACEBA8F8B97CC27

SHA256:

BD5F1CE02D7DE8999CEAAE4DAE5263D7F7D2782172E5B4F98A12007048794C2F

SSDEEP:

12288:J3e/O/epLBweExXxKvY938/O/epLBweVxXxKvYimasg8zPrS8OmmQIiB:JbGDwjoUBGDwcoRoMu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 4036)
    • Application was dropped or rewritten from another process

      • Youtube View Booster By idulkoan.exe (PID: 3504)
      • Youtube View Booster By idulkoan.exe (PID: 2364)
      • sys.exe (PID: 440)
      • Microsoft Windows Protocol Services Host.exe (PID: 2808)
      • sys.exe (PID: 1252)
      • Microsoft Windows Protocol Services Host.exe (PID: 3944)
      • Microsoft Windows Protocol Monitor.exe (PID: 3012)
    • Writes to a start menu file

      • Youtube View Booster By idulkoan.exe (PID: 3504)
      • Youtube View Booster By idulkoan.exe (PID: 2364)
    • Changes settings of System certificates

      • sys.exe (PID: 1252)
  • SUSPICIOUS

    • Writes to a desktop.ini file (may be used to cloak folders)

      • WinRAR.exe (PID: 2828)
    • Creates files in the user directory

      • Youtube View Booster By idulkoan.exe (PID: 3504)
      • sys.exe (PID: 440)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2828)
      • Youtube View Booster By idulkoan.exe (PID: 2364)
    • Creates files in the program directory

      • Youtube View Booster By idulkoan.exe (PID: 2364)
    • Creates files in the Windows directory

      • Youtube View Booster By idulkoan.exe (PID: 2364)
    • Reads internet explorer settings

      • sys.exe (PID: 440)
      • sys.exe (PID: 1252)
    • Reads Internet Cache Settings

      • sys.exe (PID: 1252)
      • sys.exe (PID: 440)
    • Adds / modifies Windows certificates

      • sys.exe (PID: 1252)
  • INFO

    • Manual execution by user

      • Youtube View Booster By idulkoan.exe (PID: 3504)
      • Youtube View Booster By idulkoan.exe (PID: 2364)
    • Dropped object may contain Bitcoin addresses

      • WinRAR.exe (PID: 2828)
      • Youtube View Booster By idulkoan.exe (PID: 2364)
    • Reads settings of System Certificates

      • sys.exe (PID: 440)
      • sys.exe (PID: 1252)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2019:03:19 05:45:07
ZipCRC: 0x5c5fd97b
ZipCompressedSize: 30932
ZipUncompressedSize: 130560
ZipFileName: Youtube View Booster V1.2/bcastdvr.proxy.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
9
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start winrar.exe searchprotocolhost.exe no specs youtube view booster by idulkoan.exe youtube view booster by idulkoan.exe microsoft windows protocol services host.exe no specs sys.exe microsoft windows protocol monitor.exe no specs microsoft windows protocol services host.exe no specs sys.exe

Process information

PID
CMD
Path
Indicators
Parent process
440"C:\Users\admin\Desktop\Youtube View Booster V1.2\WebDriver\sys.exe" {Arguments If Needed}C:\Users\admin\Desktop\Youtube View Booster V1.2\WebDriver\sys.exe
Youtube View Booster By idulkoan.exe
User:
admin
Company:
Proactive QA Solutions
Integrity Level:
MEDIUM
Description:
WindowsApplication1
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\youtube view booster v1.2\webdriver\sys.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1252"C:\Users\admin\Desktop\Youtube View Booster V1.2\WebDriver\sys.exe" {Arguments If Needed}C:\Users\admin\Desktop\Youtube View Booster V1.2\WebDriver\sys.exe
Youtube View Booster By idulkoan.exe
User:
admin
Company:
Proactive QA Solutions
Integrity Level:
HIGH
Description:
WindowsApplication1
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\youtube view booster v1.2\webdriver\sys.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2364"C:\Users\admin\Desktop\Youtube View Booster V1.2\Youtube View Booster By idulkoan.exe" C:\Users\admin\Desktop\Youtube View Booster V1.2\Youtube View Booster By idulkoan.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
interface
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\youtube view booster v1.2\youtube view booster by idulkoan.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2808"C:\Windows\Program Files (x86)\Microsoft Host Interface\WebDriver\Microsoft Windows Protocol Services Host.exe" {Arguments If Needed}C:\Windows\Program Files (x86)\Microsoft Host Interface\WebDriver\Microsoft Windows Protocol Services Host.exeYoutube View Booster By idulkoan.exe
User:
admin
Integrity Level:
HIGH
Description:
Microsoft Windows Protocol Services Host
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\windows\program files (x86)\microsoft host interface\webdriver\microsoft windows protocol services host.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2828"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Youtube View Booster V1.2.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3012"C:\Windows\Program Files (x86)\Microsoft Host Interface\WebDriver\Microsoft Windows Protocol Monitor.exe" C:\Windows\Program Files (x86)\Microsoft Host Interface\WebDriver\Microsoft Windows Protocol Monitor.exeMicrosoft Windows Protocol Services Host.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Microsoft Windows Protocol Monitor
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\windows\program files (x86)\microsoft host interface\webdriver\microsoft windows protocol monitor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3504"C:\Users\admin\Desktop\Youtube View Booster V1.2\Youtube View Booster By idulkoan.exe" C:\Users\admin\Desktop\Youtube View Booster V1.2\Youtube View Booster By idulkoan.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
interface
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\youtube view booster v1.2\youtube view booster by idulkoan.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3944"C:\Windows\Program Files (x86)\Microsoft Host Interface\WebDriver\Microsoft Windows Protocol Services Host.exe" {Arguments If Needed}C:\Windows\Program Files (x86)\Microsoft Host Interface\WebDriver\Microsoft Windows Protocol Services Host.exeYoutube View Booster By idulkoan.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Microsoft Windows Protocol Services Host
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\windows\program files (x86)\microsoft host interface\webdriver\microsoft windows protocol services host.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
4036"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
2 528
Read events
1 279
Write events
1 249
Delete events
0

Modification events

(PID) Process:(2828) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2828) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2828) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2828) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12D\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(2828) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Youtube View Booster V1.2.zip
(PID) Process:(2828) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2828) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2828) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2828) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2828) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
Executable files
12
Suspicious files
4
Text files
14
Unknown types
4

Dropped files

PID
Process
Filename
Type
3504Youtube View Booster By idulkoan.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Startup.lnklnk
MD5:
SHA256:
440sys.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CFE86DBBE02D859DC92F1E17E0574EE8_46766FC45507C0B9E264E4C18BC7288Bder
MD5:
SHA256:
2364Youtube View Booster By idulkoan.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Startup.lnklnk
MD5:
SHA256:
440sys.exeC:\Users\admin\AppData\Local\Temp\CabDE87.tmp
MD5:
SHA256:
440sys.exeC:\Users\admin\AppData\Local\Temp\TarDE88.tmp
MD5:
SHA256:
440sys.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\HHH0DJY0.txttext
MD5:
SHA256:
440sys.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CFE86DBBE02D859DC92F1E17E0574EE8_46766FC45507C0B9E264E4C18BC7288Bbinary
MD5:
SHA256:
2828WinRAR.exeC:\Users\admin\Desktop\Youtube View Booster V1.2\bcastdvr.proxy.dllexecutable
MD5:EB1E9D853B3A71F8DB7DE8A1EE04A757
SHA256:610AB0B7BEE791A97E1EBB78A71897ADCDAD3E1DB53598A1E1FBA0B3CAE624C3
2828WinRAR.exeC:\Users\admin\Desktop\Youtube View Booster V1.2\WebDriver\d3dx10_43.dllexecutable
MD5:20C835843FCEC4DEDFCD7BFFA3B91641
SHA256:56FCD13650FD1F075743154E8C48465DD68A236AB8960667D75373139D2631BF
2828WinRAR.exeC:\Users\admin\Desktop\Youtube View Booster V1.2\WebDriver\eappcfg.dllexecutable
MD5:A6A7CB08C09AEE9404D07DF5DC2AA028
SHA256:1EC82E8A5F456DF22A23B2A155E2AF398C0DC5C01CB3F0CC09A41EB88C2ED1E3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
11
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
440
sys.exe
GET
200
172.217.22.35:80
http://ocsp.pki.goog/gts1o1/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEQCb8YvXm0ZYmQIAAAAAY5hx
US
der
472 b
whitelisted
1252
sys.exe
GET
301
172.217.23.174:80
http://www.youtube.com/user/idulkoan
US
whitelisted
440
sys.exe
GET
301
172.217.23.174:80
http://www.youtube.com/user/idulkoan
US
whitelisted
440
sys.exe
GET
200
172.217.22.35:80
http://ocsp.pki.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjtJqhjYqpgSVpULg%3D
US
der
468 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
440
sys.exe
172.217.23.174:80
www.youtube.com
Google Inc.
US
whitelisted
440
sys.exe
172.217.23.174:443
www.youtube.com
Google Inc.
US
whitelisted
440
sys.exe
172.217.22.35:80
ocsp.pki.goog
Google Inc.
US
whitelisted
440
sys.exe
172.217.23.142:443
www.youtube.com
Google Inc.
US
whitelisted
1252
sys.exe
172.217.23.174:80
www.youtube.com
Google Inc.
US
whitelisted
1252
sys.exe
172.217.23.174:443
www.youtube.com
Google Inc.
US
whitelisted
1252
sys.exe
172.217.23.142:443
www.youtube.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
www.youtube.com
  • 172.217.23.174
  • 172.217.23.142
  • 216.58.205.238
  • 172.217.22.14
  • 216.58.207.78
  • 172.217.16.142
  • 172.217.16.206
  • 172.217.23.110
  • 216.58.212.142
  • 172.217.22.46
  • 172.217.22.78
whitelisted
ocsp.pki.goog
  • 172.217.22.35
whitelisted
s.ytimg.com
  • 172.217.23.142
whitelisted

Threats

No threats detected
No debug info