File name:

Youtube View Booster V1.2.zip

Full analysis: https://app.any.run/tasks/f102884e-95a8-4ff9-8495-182753b8ae44
Verdict: Malicious activity
Analysis date: May 09, 2020, 16:23:09
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

E43908C1B77CB6FE6069524C42C8C703

SHA1:

4F2E8B0F6FEEC62A7A81D6961ACEBA8F8B97CC27

SHA256:

BD5F1CE02D7DE8999CEAAE4DAE5263D7F7D2782172E5B4F98A12007048794C2F

SSDEEP:

12288:J3e/O/epLBweExXxKvY938/O/epLBweVxXxKvYimasg8zPrS8OmmQIiB:JbGDwjoUBGDwcoRoMu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Youtube View Booster By idulkoan.exe (PID: 3504)
      • Youtube View Booster By idulkoan.exe (PID: 2364)
      • Microsoft Windows Protocol Services Host.exe (PID: 3944)
      • sys.exe (PID: 440)
      • Microsoft Windows Protocol Monitor.exe (PID: 3012)
      • sys.exe (PID: 1252)
      • Microsoft Windows Protocol Services Host.exe (PID: 2808)
    • Writes to a start menu file

      • Youtube View Booster By idulkoan.exe (PID: 3504)
      • Youtube View Booster By idulkoan.exe (PID: 2364)
    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 4036)
    • Changes settings of System certificates

      • sys.exe (PID: 1252)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2828)
      • Youtube View Booster By idulkoan.exe (PID: 2364)
    • Writes to a desktop.ini file (may be used to cloak folders)

      • WinRAR.exe (PID: 2828)
    • Creates files in the user directory

      • Youtube View Booster By idulkoan.exe (PID: 3504)
      • sys.exe (PID: 440)
    • Creates files in the Windows directory

      • Youtube View Booster By idulkoan.exe (PID: 2364)
    • Reads Internet Cache Settings

      • sys.exe (PID: 440)
      • sys.exe (PID: 1252)
    • Reads internet explorer settings

      • sys.exe (PID: 440)
      • sys.exe (PID: 1252)
    • Creates files in the program directory

      • Youtube View Booster By idulkoan.exe (PID: 2364)
    • Adds / modifies Windows certificates

      • sys.exe (PID: 1252)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • WinRAR.exe (PID: 2828)
      • Youtube View Booster By idulkoan.exe (PID: 2364)
    • Manual execution by user

      • Youtube View Booster By idulkoan.exe (PID: 3504)
      • Youtube View Booster By idulkoan.exe (PID: 2364)
    • Reads settings of System Certificates

      • sys.exe (PID: 440)
      • sys.exe (PID: 1252)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2019:03:19 05:45:07
ZipCRC: 0x5c5fd97b
ZipCompressedSize: 30932
ZipUncompressedSize: 130560
ZipFileName: Youtube View Booster V1.2/bcastdvr.proxy.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
9
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start winrar.exe searchprotocolhost.exe no specs youtube view booster by idulkoan.exe youtube view booster by idulkoan.exe microsoft windows protocol services host.exe no specs sys.exe microsoft windows protocol monitor.exe no specs microsoft windows protocol services host.exe no specs sys.exe

Process information

PID
CMD
Path
Indicators
Parent process
440"C:\Users\admin\Desktop\Youtube View Booster V1.2\WebDriver\sys.exe" {Arguments If Needed}C:\Users\admin\Desktop\Youtube View Booster V1.2\WebDriver\sys.exe
Youtube View Booster By idulkoan.exe
User:
admin
Company:
Proactive QA Solutions
Integrity Level:
MEDIUM
Description:
WindowsApplication1
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\youtube view booster v1.2\webdriver\sys.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1252"C:\Users\admin\Desktop\Youtube View Booster V1.2\WebDriver\sys.exe" {Arguments If Needed}C:\Users\admin\Desktop\Youtube View Booster V1.2\WebDriver\sys.exe
Youtube View Booster By idulkoan.exe
User:
admin
Company:
Proactive QA Solutions
Integrity Level:
HIGH
Description:
WindowsApplication1
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\youtube view booster v1.2\webdriver\sys.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2364"C:\Users\admin\Desktop\Youtube View Booster V1.2\Youtube View Booster By idulkoan.exe" C:\Users\admin\Desktop\Youtube View Booster V1.2\Youtube View Booster By idulkoan.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
interface
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\youtube view booster v1.2\youtube view booster by idulkoan.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2808"C:\Windows\Program Files (x86)\Microsoft Host Interface\WebDriver\Microsoft Windows Protocol Services Host.exe" {Arguments If Needed}C:\Windows\Program Files (x86)\Microsoft Host Interface\WebDriver\Microsoft Windows Protocol Services Host.exeYoutube View Booster By idulkoan.exe
User:
admin
Integrity Level:
HIGH
Description:
Microsoft Windows Protocol Services Host
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\windows\program files (x86)\microsoft host interface\webdriver\microsoft windows protocol services host.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2828"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Youtube View Booster V1.2.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3012"C:\Windows\Program Files (x86)\Microsoft Host Interface\WebDriver\Microsoft Windows Protocol Monitor.exe" C:\Windows\Program Files (x86)\Microsoft Host Interface\WebDriver\Microsoft Windows Protocol Monitor.exeMicrosoft Windows Protocol Services Host.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Microsoft Windows Protocol Monitor
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\windows\program files (x86)\microsoft host interface\webdriver\microsoft windows protocol monitor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3504"C:\Users\admin\Desktop\Youtube View Booster V1.2\Youtube View Booster By idulkoan.exe" C:\Users\admin\Desktop\Youtube View Booster V1.2\Youtube View Booster By idulkoan.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
interface
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\youtube view booster v1.2\youtube view booster by idulkoan.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3944"C:\Windows\Program Files (x86)\Microsoft Host Interface\WebDriver\Microsoft Windows Protocol Services Host.exe" {Arguments If Needed}C:\Windows\Program Files (x86)\Microsoft Host Interface\WebDriver\Microsoft Windows Protocol Services Host.exeYoutube View Booster By idulkoan.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Microsoft Windows Protocol Services Host
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\windows\program files (x86)\microsoft host interface\webdriver\microsoft windows protocol services host.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
4036"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
2 528
Read events
1 279
Write events
1 249
Delete events
0

Modification events

(PID) Process:(2828) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2828) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2828) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2828) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12D\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(2828) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Youtube View Booster V1.2.zip
(PID) Process:(2828) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2828) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2828) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2828) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2828) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
Executable files
12
Suspicious files
4
Text files
14
Unknown types
4

Dropped files

PID
Process
Filename
Type
2828WinRAR.exeC:\Users\admin\Desktop\Youtube View Booster V1.2\Virus Total\desktop.iniini
MD5:C279803B27F13369AA54FC9B84B72468
SHA256:D80758A34364CAB9DE42FF6ED57BCC753A0936DDDDF9952C5B4FB9FF0D7966C9
3504Youtube View Booster By idulkoan.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Startup.lnklnk
MD5:
SHA256:
2828WinRAR.exeC:\Users\admin\Desktop\Youtube View Booster V1.2\Change log.txttext
MD5:58D0F08D1E7AC67A1FD33CC82318328E
SHA256:77A2237297CD8AB1F654293716D265AA15AC605A2D0D189425603860C31F6D9D
440sys.exeC:\Users\admin\AppData\Local\Temp\CabDE87.tmp
MD5:
SHA256:
440sys.exeC:\Users\admin\AppData\Local\Temp\TarDE88.tmp
MD5:
SHA256:
440sys.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CFE86DBBE02D859DC92F1E17E0574EE8_46766FC45507C0B9E264E4C18BC7288Bder
MD5:
SHA256:
440sys.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CFE86DBBE02D859DC92F1E17E0574EE8_46766FC45507C0B9E264E4C18BC7288Bbinary
MD5:
SHA256:
2828WinRAR.exeC:\Users\admin\Desktop\Youtube View Booster V1.2\Youtube View Booster By idulkoan.exeexecutable
MD5:
SHA256:
2364Youtube View Booster By idulkoan.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Startup.lnklnk
MD5:
SHA256:
440sys.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\HHH0DJY0.txttext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
11
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1252
sys.exe
GET
301
172.217.23.174:80
http://www.youtube.com/user/idulkoan
US
whitelisted
440
sys.exe
GET
301
172.217.23.174:80
http://www.youtube.com/user/idulkoan
US
whitelisted
440
sys.exe
GET
200
172.217.22.35:80
http://ocsp.pki.goog/gts1o1/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEQCb8YvXm0ZYmQIAAAAAY5hx
US
der
472 b
whitelisted
440
sys.exe
GET
200
172.217.22.35:80
http://ocsp.pki.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjtJqhjYqpgSVpULg%3D
US
der
468 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
440
sys.exe
172.217.23.174:80
www.youtube.com
Google Inc.
US
whitelisted
440
sys.exe
172.217.23.174:443
www.youtube.com
Google Inc.
US
whitelisted
440
sys.exe
172.217.22.35:80
ocsp.pki.goog
Google Inc.
US
whitelisted
440
sys.exe
172.217.23.142:443
www.youtube.com
Google Inc.
US
whitelisted
1252
sys.exe
172.217.23.174:80
www.youtube.com
Google Inc.
US
whitelisted
1252
sys.exe
172.217.23.174:443
www.youtube.com
Google Inc.
US
whitelisted
1252
sys.exe
172.217.23.142:443
www.youtube.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
www.youtube.com
  • 172.217.23.174
  • 172.217.23.142
  • 216.58.205.238
  • 172.217.22.14
  • 216.58.207.78
  • 172.217.16.142
  • 172.217.16.206
  • 172.217.23.110
  • 216.58.212.142
  • 172.217.22.46
  • 172.217.22.78
whitelisted
ocsp.pki.goog
  • 172.217.22.35
whitelisted
s.ytimg.com
  • 172.217.23.142
whitelisted

Threats

No threats detected
No debug info