File name:

GatherProxy NoPremi New.7z

Full analysis: https://app.any.run/tasks/99b66d0f-a8a4-4906-9013-5d5fd6033ca4
Verdict: Malicious activity
Analysis date: April 08, 2018, 14:19:09
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

C3D74C0683374ED1BC7CEDF1E28C0241

SHA1:

F076C8EFD918CD0E328E6BA1E8672D8347673BE9

SHA256:

BE0130583B14B0EF65760A576D2B2304C1CB9768832C5741A888480BD34D5CB7

SSDEEP:

49152:Ce/IU0RfdgNhnX9l3QCzAKb4bXLeIhkmYp/Bm0TkiYfUEk8HBpBLD4stAUT0Po:CegldKD34jLeyYppm0TdYfU8TB31rYA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Gather Proxy.exe (PID: 2180)
    • Application loaded dropped or rewritten executable

      • Gather Proxy.exe (PID: 2180)
      • SearchProtocolHost.exe (PID: 1512)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Loads the .NET runtime environment

      • Gather Proxy.exe (PID: 2180)
    • Loads rich edit control libraries

      • Gather Proxy.exe (PID: 2180)
    • Dropped object may contain URL's

      • 7zFM.exe (PID: 2564)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 7zfm.exe searchprotocolhost.exe no specs gather proxy.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1512"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2180"C:\Users\admin\Desktop\GatherProxy NoPremi New\Gather Proxy.exe" C:\Users\admin\Desktop\GatherProxy NoPremi New\Gather Proxy.exeexplorer.exe
User:
admin
Company:
GatherProxy.com
Integrity Level:
MEDIUM
Description:
Gather Proxy 9.0 - Free Pro Proxy and Socks Scraper
Exit code:
0
Version:
9.0.0.0
Modules
Images
c:\users\admin\desktop\gatherproxy nopremi new\gather proxy.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2564"C:\Program Files\7-Zip\7zFM.exe" "C:\Users\admin\AppData\Local\Temp\GatherProxy NoPremi New.7z"C:\Program Files\7-Zip\7zFM.exe
explorer.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip File Manager
Exit code:
0
Version:
16.04
Modules
Images
c:\program files\7-zip\7zfm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
424
Read events
411
Write events
13
Delete events
0

Modification events

(PID) Process:(2564) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:CopyHistory
Value:
43003A005C00550073006500720073005C00610064006D0069006E005C004400650073006B0074006F0070000000
(PID) Process:(2564) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM\Columns
Operation:writeName:7-Zip.7z
Value:
0100000004000000010000000400000001000000A00000000700000001000000640000000800000001000000640000000C00000001000000640000000900000001000000640000001300000001000000640000000F00000001000000640000001600000001000000640000001B00000001000000640000001F0000000100000064000000200000000100000064000000
(PID) Process:(1512) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\91\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1512) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\91\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
(PID) Process:(2564) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:FolderShortcuts
Value:
(PID) Process:(2564) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:FolderHistory
Value:
43003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C00540065006D0070005C00470061007400680065007200500072006F007800790020004E006F005000720065006D00690020004E00650077002E0037007A005C000000
(PID) Process:(2564) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:PanelPath0
Value:
C:\Users\admin\AppData\Local\Temp\
(PID) Process:(2564) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:FlatViewArc0
Value:
0
(PID) Process:(2564) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:PanelPath1
Value:
(PID) Process:(2564) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:FlatViewArc1
Value:
0
Executable files
11
Suspicious files
0
Text files
8
Unknown types
1

Dropped files

PID
Process
Filename
Type
25647zFM.exeC:\Users\admin\Desktop\GatherProxy NoPremi New\Data\agents.txttext
MD5:8520DC38FF84C55CEFA74D492D271DA4
SHA256:FC73F46883AECB0AC9C944A2756CA2CF1AC0E60F963D92700C0DD62EADC3D72B
25647zFM.exeC:\Users\admin\Desktop\GatherProxy NoPremi New\Data\autosp.initext
MD5:0AB7386476BFD6E6A7FDCAA91DA04D4F
SHA256:BA4DB1C4843A36822F68556D4F2AC5B815F3E7B063D28D8905FD6084B594EC40
25647zFM.exeC:\Users\admin\Desktop\GatherProxy NoPremi New\Data\geo.mmdbmpg
MD5:B3AD53256708B3A42E223F506A7792FF
SHA256:E3B77E008345EDE8AF053FD660B915BEF1D1D956BD34921935A0C08FFF4837B8
25647zFM.exeC:\Users\admin\Desktop\GatherProxy NoPremi New\Gather Proxy.exeexecutable
MD5:BC1566DD4D2D5A483E5F536060A4069B
SHA256:12551869311CC0991E088E3A4607F44638FC5F87F787B71152983B5ADF717CD9
25647zFM.exeC:\Users\admin\Desktop\GatherProxy NoPremi New\Data\configs.gptext
MD5:84592DF7DFBE37A0FFD354ACC32EC930
SHA256:908A674AED0DC3815DEA44B67FA3290DA8B2B544C136FB14AD2EC4D696F692E4
25647zFM.exeC:\Users\admin\Desktop\GatherProxy NoPremi New\GC.dllexecutable
MD5:BEA3694CC7C60877D1B3C07DE352ADAB
SHA256:CEDB323B29D5C3104EB42D39E93AECC5CC3A69D2BA507F732F176A7051ECBCC3
25647zFM.exeC:\Users\admin\Desktop\GatherProxy NoPremi New\Data\planetlab.txttext
MD5:4AA755C53F5741125462955E02440DD1
SHA256:B26C86587F82AE186D1860BD03F71858C74F2E1DBA624E7FF85A9DE67FE80D56
25647zFM.exeC:\Users\admin\Desktop\GatherProxy NoPremi New\Data\referrals.txttext
MD5:B5CE4C46FD94C0F038FB7E04B1EF6666
SHA256:04983579DE0B2559D6E55E6447AB60FA1AC97A8DE7FC91B79899DB496571736F
25647zFM.exeC:\Users\admin\Desktop\GatherProxy NoPremi New\Data\ref.reftext
MD5:EDF1E41F9FE226BE3E61845B747A2C6E
SHA256:C78BA0953491DCCBD7EE2B03CF6AE3A295676715D524B278345FBB31245FBCD5
25647zFM.exeC:\Users\admin\Desktop\GatherProxy NoPremi New\Gather Proxy.exe.configxml
MD5:365E8A1FAE1391145F187F048680FC08
SHA256:40A15F3B0184FB80CC36F771B589D2338CDA22EBC2F0EF0711E0C69B4DBCE4CC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
3
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
97.74.233.74:80
http://update.snaware.com/auth/?k=FGgm97uhO1RRcmTA7xO1%2fulskJPqPL1KiVjOimD%2bqDwzisxVriNNgOot5l5McIYtLEaNnUZkP67T8n9uaRTVrkFQZsYL8gjdvGfs%2fs3aTTSFGhQxKEnx34xBmWARI8bba8vbF4c0bnmaBFGbpJG%2fzHb5CmmC2ptkGUomill2Ub6mZG4xbPl3eiYSXLfjPI74
US
malicious
GET
97.74.233.74:80
http://update.snaware.com/auth/?k=FGgm97uhO1RRcmTA7xO1%2fulskJPqPL1KiVjOimD%2bqDwzisxVriNNgOot5l5McIYtLEaNnUZkP67T8n9uaRTVrkFQZsYL8gjdvGfs%2fs3aTTSFGhQxKEnx34xBmWARI8bba8vbF4c0bnmaBFGbpJG%2fzHb5CmmC2ptkGUomill2Ub6mZG4xbPl3eiYSXLfjPI74
US
malicious
GET
200
97.74.233.74:80
http://update.snaware.com/auth/?k=FGgm97uhO1RRcmTA7xO1%2fulskJPqPL1KiVjOimD%2bqDwzisxVriNNgOot5l5McIYtLEaNnUZkP67T8n9uaRTVrkFQZsYL8gjdvGfs%2fs3aTTSFGhQxKEnx34xBmWARI8bba8vbF4c0bnmaBFGbpJG%2fzHb5CmmC2ptkGUomill2Ub6mZG4xbPl3eiYSXLfjPI74
US
text
1.29 Kb
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
97.74.233.74:80
update.snaware.com
GoDaddy.com, LLC
US
unknown

DNS requests

Domain
IP
Reputation
update.snaware.com
  • 97.74.233.74
malicious

Threats

No threats detected
No debug info