| File name: | GatherProxy NoPremi New.7z |
| Full analysis: | https://app.any.run/tasks/99b66d0f-a8a4-4906-9013-5d5fd6033ca4 |
| Verdict: | Malicious activity |
| Analysis date: | April 08, 2018, 14:19:09 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-7z-compressed |
| File info: | 7-zip archive data, version 0.4 |
| MD5: | C3D74C0683374ED1BC7CEDF1E28C0241 |
| SHA1: | F076C8EFD918CD0E328E6BA1E8672D8347673BE9 |
| SHA256: | BE0130583B14B0EF65760A576D2B2304C1CB9768832C5741A888480BD34D5CB7 |
| SSDEEP: | 49152:Ce/IU0RfdgNhnX9l3QCzAKb4bXLeIhkmYp/Bm0TkiYfUEk8HBpBLD4stAUT0Po:CegldKD34jLeyYppm0TdYfU8TB31rYA |
| .7z | | | 7-Zip compressed archive (v0.4) (57.1) |
|---|---|---|
| .7z | | | 7-Zip compressed archive (gen) (42.8) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1512 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\System32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2180 | "C:\Users\admin\Desktop\GatherProxy NoPremi New\Gather Proxy.exe" | C:\Users\admin\Desktop\GatherProxy NoPremi New\Gather Proxy.exe | — | explorer.exe | |||||||||||
User: admin Company: GatherProxy.com Integrity Level: MEDIUM Description: Gather Proxy 9.0 - Free Pro Proxy and Socks Scraper Exit code: 0 Version: 9.0.0.0 Modules
| |||||||||||||||
| 2564 | "C:\Program Files\7-Zip\7zFM.exe" "C:\Users\admin\AppData\Local\Temp\GatherProxy NoPremi New.7z" | C:\Program Files\7-Zip\7zFM.exe | explorer.exe | ||||||||||||
User: admin Company: Igor Pavlov Integrity Level: MEDIUM Description: 7-Zip File Manager Exit code: 0 Version: 16.04 Modules
| |||||||||||||||
| (PID) Process: | (2564) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\7-Zip\FM |
| Operation: | write | Name: | CopyHistory |
Value: 43003A005C00550073006500720073005C00610064006D0069006E005C004400650073006B0074006F0070000000 | |||
| (PID) Process: | (2564) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\7-Zip\FM\Columns |
| Operation: | write | Name: | 7-Zip.7z |
Value: 0100000004000000010000000400000001000000A00000000700000001000000640000000800000001000000640000000C00000001000000640000000900000001000000640000001300000001000000640000000F00000001000000640000001600000001000000640000001B00000001000000640000001F0000000100000064000000200000000100000064000000 | |||
| (PID) Process: | (1512) SearchProtocolHost.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\91\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1512) SearchProtocolHost.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\91\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\notepad.exe,-469 |
Value: Text Document | |||
| (PID) Process: | (2564) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\7-Zip\FM |
| Operation: | write | Name: | FolderShortcuts |
Value: | |||
| (PID) Process: | (2564) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\7-Zip\FM |
| Operation: | write | Name: | FolderHistory |
Value: 43003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C00540065006D0070005C00470061007400680065007200500072006F007800790020004E006F005000720065006D00690020004E00650077002E0037007A005C000000 | |||
| (PID) Process: | (2564) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\7-Zip\FM |
| Operation: | write | Name: | PanelPath0 |
Value: C:\Users\admin\AppData\Local\Temp\ | |||
| (PID) Process: | (2564) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\7-Zip\FM |
| Operation: | write | Name: | FlatViewArc0 |
Value: 0 | |||
| (PID) Process: | (2564) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\7-Zip\FM |
| Operation: | write | Name: | PanelPath1 |
Value: | |||
| (PID) Process: | (2564) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\7-Zip\FM |
| Operation: | write | Name: | FlatViewArc1 |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2564 | 7zFM.exe | C:\Users\admin\Desktop\GatherProxy NoPremi New\Data\agents.txt | text | |
MD5:8520DC38FF84C55CEFA74D492D271DA4 | SHA256:FC73F46883AECB0AC9C944A2756CA2CF1AC0E60F963D92700C0DD62EADC3D72B | |||
| 2564 | 7zFM.exe | C:\Users\admin\Desktop\GatherProxy NoPremi New\Data\autosp.ini | text | |
MD5:0AB7386476BFD6E6A7FDCAA91DA04D4F | SHA256:BA4DB1C4843A36822F68556D4F2AC5B815F3E7B063D28D8905FD6084B594EC40 | |||
| 2564 | 7zFM.exe | C:\Users\admin\Desktop\GatherProxy NoPremi New\Data\geo.mmdb | mpg | |
MD5:B3AD53256708B3A42E223F506A7792FF | SHA256:E3B77E008345EDE8AF053FD660B915BEF1D1D956BD34921935A0C08FFF4837B8 | |||
| 2564 | 7zFM.exe | C:\Users\admin\Desktop\GatherProxy NoPremi New\Gather Proxy.exe | executable | |
MD5:BC1566DD4D2D5A483E5F536060A4069B | SHA256:12551869311CC0991E088E3A4607F44638FC5F87F787B71152983B5ADF717CD9 | |||
| 2564 | 7zFM.exe | C:\Users\admin\Desktop\GatherProxy NoPremi New\Data\configs.gp | text | |
MD5:84592DF7DFBE37A0FFD354ACC32EC930 | SHA256:908A674AED0DC3815DEA44B67FA3290DA8B2B544C136FB14AD2EC4D696F692E4 | |||
| 2564 | 7zFM.exe | C:\Users\admin\Desktop\GatherProxy NoPremi New\GC.dll | executable | |
MD5:BEA3694CC7C60877D1B3C07DE352ADAB | SHA256:CEDB323B29D5C3104EB42D39E93AECC5CC3A69D2BA507F732F176A7051ECBCC3 | |||
| 2564 | 7zFM.exe | C:\Users\admin\Desktop\GatherProxy NoPremi New\Data\planetlab.txt | text | |
MD5:4AA755C53F5741125462955E02440DD1 | SHA256:B26C86587F82AE186D1860BD03F71858C74F2E1DBA624E7FF85A9DE67FE80D56 | |||
| 2564 | 7zFM.exe | C:\Users\admin\Desktop\GatherProxy NoPremi New\Data\referrals.txt | text | |
MD5:B5CE4C46FD94C0F038FB7E04B1EF6666 | SHA256:04983579DE0B2559D6E55E6447AB60FA1AC97A8DE7FC91B79899DB496571736F | |||
| 2564 | 7zFM.exe | C:\Users\admin\Desktop\GatherProxy NoPremi New\Data\ref.ref | text | |
MD5:EDF1E41F9FE226BE3E61845B747A2C6E | SHA256:C78BA0953491DCCBD7EE2B03CF6AE3A295676715D524B278345FBB31245FBCD5 | |||
| 2564 | 7zFM.exe | C:\Users\admin\Desktop\GatherProxy NoPremi New\Gather Proxy.exe.config | xml | |
MD5:365E8A1FAE1391145F187F048680FC08 | SHA256:40A15F3B0184FB80CC36F771B589D2338CDA22EBC2F0EF0711E0C69B4DBCE4CC | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | — | 97.74.233.74:80 | http://update.snaware.com/auth/?k=FGgm97uhO1RRcmTA7xO1%2fulskJPqPL1KiVjOimD%2bqDwzisxVriNNgOot5l5McIYtLEaNnUZkP67T8n9uaRTVrkFQZsYL8gjdvGfs%2fs3aTTSFGhQxKEnx34xBmWARI8bba8vbF4c0bnmaBFGbpJG%2fzHb5CmmC2ptkGUomill2Ub6mZG4xbPl3eiYSXLfjPI74 | US | — | — | malicious |
— | — | GET | — | 97.74.233.74:80 | http://update.snaware.com/auth/?k=FGgm97uhO1RRcmTA7xO1%2fulskJPqPL1KiVjOimD%2bqDwzisxVriNNgOot5l5McIYtLEaNnUZkP67T8n9uaRTVrkFQZsYL8gjdvGfs%2fs3aTTSFGhQxKEnx34xBmWARI8bba8vbF4c0bnmaBFGbpJG%2fzHb5CmmC2ptkGUomill2Ub6mZG4xbPl3eiYSXLfjPI74 | US | — | — | malicious |
— | — | GET | 200 | 97.74.233.74:80 | http://update.snaware.com/auth/?k=FGgm97uhO1RRcmTA7xO1%2fulskJPqPL1KiVjOimD%2bqDwzisxVriNNgOot5l5McIYtLEaNnUZkP67T8n9uaRTVrkFQZsYL8gjdvGfs%2fs3aTTSFGhQxKEnx34xBmWARI8bba8vbF4c0bnmaBFGbpJG%2fzHb5CmmC2ptkGUomill2Ub6mZG4xbPl3eiYSXLfjPI74 | US | text | 1.29 Kb | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 97.74.233.74:80 | update.snaware.com | GoDaddy.com, LLC | US | unknown |
Domain | IP | Reputation |
|---|---|---|
update.snaware.com |
| malicious |