File name:

Facebook A_ounts Checker v1.0 By X-LINE.zip

Full analysis: https://app.any.run/tasks/e7cf67ab-d63f-4fbe-aa5a-92dd65477833
Verdict: Malicious activity
Analysis date: November 29, 2020, 11:02:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

5F45CDA0CCE34CCAFB11C517F827BCC0

SHA1:

EF3155CC43594E44002CE43FDA68376AFA8DD96B

SHA256:

CD537EE137A511B1CE6718EC998C4714576442602618F4937F8537826C0356CF

SSDEEP:

98304:OlYFLtFrkJsTh0sula4spTvRl3JhQ2h+9G4T:QoLtFI96jJvbZhQaoH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3352)
      • Facebook Accounts Checker v1.0 By X-LINE.exe (PID: 2500)
    • Application was dropped or rewritten from another process

      • Facebook Accounts Checker v1.0 By X-LINE.exe (PID: 2500)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2824)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 2824)
  • INFO

    • Manual execution by user

      • Facebook Accounts Checker v1.0 By X-LINE.exe (PID: 2500)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2018:01:15 16:04:20
ZipCRC: 0xf8601491
ZipCompressedSize: 95741
ZipUncompressedSize: 312832
ZipFileName: MetroSuite 2.0.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
3
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs facebook accounts checker v1.0 by x-line.exe

Process information

PID
CMD
Path
Indicators
Parent process
2500"C:\Users\admin\Desktop\Facebook A_ounts Checker v1.0 By X-LINE\Facebook Accounts Checker v1.0 By X-LINE.exe" C:\Users\admin\Desktop\Facebook A_ounts Checker v1.0 By X-LINE\Facebook Accounts Checker v1.0 By X-LINE.exe
explorer.exe
User:
admin
Company:
Facebook Accounts Checker v1.0 | X-LINE
Integrity Level:
MEDIUM
Description:
Facebook Accounts Checker v1.0 | X-LINE
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\facebook a_ounts checker v1.0 by x-line\facebook accounts checker v1.0 by x-line.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2824"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Facebook A_ounts Checker v1.0 By X-LINE.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3352"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
858
Read events
837
Write events
21
Delete events
0

Modification events

(PID) Process:(2824) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2824) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2824) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2824) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Facebook A_ounts Checker v1.0 By X-LINE.zip
(PID) Process:(2824) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2824) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2824) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2824) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2824) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Facebook A_ounts Checker v1.0 By X-LINE
(PID) Process:(2824) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
6
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2824WinRAR.exeC:\Users\admin\Desktop\Facebook A_ounts Checker v1.0 By X-LINE\MetroSuite 2.0.dllexecutable
MD5:0D30A398CEC0FF006B6EA2B52D11E744
SHA256:8604BF2A1FE2E94DC1EA1FBD0CF54E77303493B93994DF48479DC683580AA654
2500Facebook Accounts Checker v1.0 By X-LINE.exeC:\Users\admin\Desktop\Facebook A_ounts Checker v1.0 By X-LINE\Results\Screenshot.pngimage
MD5:
SHA256:
2824WinRAR.exeC:\Users\admin\Desktop\Facebook A_ounts Checker v1.0 By X-LINE\Telegram.dllexecutable
MD5:6414789D627BB6D9EAD597299A5F0876
SHA256:A8E23A56F95632A947DF8ADBED260929EECC3F41138CDB5280A3B97574A4A005
2824WinRAR.exeC:\Users\admin\Desktop\Facebook A_ounts Checker v1.0 By X-LINE\Facebook Accounts Checker v1.0 By X-LINE.exeexecutable
MD5:B2074630268DEE3B475A17BDC0648A2E
SHA256:29C55D431FB3CCAE1592BE8DA3DA8250205CF009786FDB1E808B3C9FE5D4122F
2824WinRAR.exeC:\Users\admin\Desktop\Facebook A_ounts Checker v1.0 By X-LINE\xNet.dllexecutable
MD5:AC1DCEDDBC66A1AB7915AC9931F0CFEC
SHA256:CC949931EF9533ADCED83F3D58862E9732E5DB7AD17B5FD4CB9D209A99EDB592
2824WinRAR.exeC:\Users\admin\Desktop\Facebook A_ounts Checker v1.0 By X-LINE\Facebook Accounts Checker v10 By X-LINE64.dllexecutable
MD5:ADF108AF551793F9883E5FF77070B826
SHA256:835305F52DD417990CD13F8D1B71C77BC2F93CF5CBC1647F1A4F7AC3ECD24674
2824WinRAR.exeC:\Users\admin\Desktop\Facebook A_ounts Checker v1.0 By X-LINE\Facebook Accounts Checker v10 By X-LINE32.dllexecutable
MD5:54FB01CC27DE40B955FD59AAD9AFB0D2
SHA256:D3B44E0DCEB22FAB65F0ACFA09FF136916FCD45DA51DACC338A969E85A5BDAD7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2500
Facebook Accounts Checker v1.0 By X-LINE.exe
91.134.128.45:443
api.proxyscrape.com
OVH SAS
FR
suspicious

DNS requests

Domain
IP
Reputation
api.proxyscrape.com
  • 91.134.128.45
suspicious

Threats

No threats detected
No debug info