File name:

AwesomeMiner7.3_patch.zip

Full analysis: https://app.any.run/tasks/64399f95-083a-4bec-90d1-c94d97ee6082
Verdict: Malicious activity
Threats:

Crypto mining malware is a resource-intensive threat that infiltrates computers with the purpose of mining cryptocurrencies. This type of threat can be deployed either on an infected machine or a compromised website. In both cases the miner will utilize the computing power of the device and its network bandwidth.

Analysis date: February 12, 2020, 12:53:21
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
miner
trojan
stealer
grandsteal
evasion
rat
quasar
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

DBFF5198F31D0BE231691F9300985DCC

SHA1:

391F7C24CDC66ED58ADF0EBE82A28DA4FCF27EFB

SHA256:

DF4CF2041A553E51067387F977A423B25B31607752915D4B167CF33AAA75DFCA

SSDEEP:

196608:vrpn7dVXDi2V9o3yc7hRCLcgBQ54qIqEvyk7Ul8anUWh76dLHH/Me1+KJs/5TemY:ZnXDVw4BQ2zRa6Ull/SHfMu+1dr8d

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • IntelliBreeze.Maintenance.Service.exe (PID: 1676)
      • AwesomeMiner.exe (PID: 2756)
    • Application was dropped or rewritten from another process

      • IntelliBreeze.Maintenance.Service.exe (PID: 1676)
      • AwesomeMiner.exe (PID: 2756)
      • AwesomeCrack.exe (PID: 3768)
    • Loads the Task Scheduler COM API

      • IntelliBreeze.Maintenance.Service.exe (PID: 1676)
    • GRANDSTEAL was detected

      • AwesomeCrack.exe (PID: 3768)
    • QUASAR was detected

      • AwesomeCrack.exe (PID: 3768)
    • Stealing of credential data

      • AwesomeCrack.exe (PID: 3768)
  • SUSPICIOUS

    • Executed as Windows Service

      • vssvc.exe (PID: 3252)
      • IntelliBreeze.Maintenance.Service.exe (PID: 1676)
    • Creates files in the program directory

      • IntelliBreeze.Maintenance.Service.exe (PID: 1676)
      • AwesomeMiner.exe (PID: 2756)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3420)
      • msiexec.exe (PID: 2340)
      • msiexec.exe (PID: 3428)
    • Dropped object may contain URLs of mainers pools

      • msiexec.exe (PID: 2340)
      • AwesomeMiner.exe (PID: 2756)
    • Reads Environment values

      • AwesomeMiner.exe (PID: 2756)
      • AwesomeCrack.exe (PID: 3768)
    • Modifies the open verb of a shell class

      • msiexec.exe (PID: 2340)
      • AwesomeMiner.exe (PID: 2756)
    • Creates files in the user directory

      • AwesomeMiner.exe (PID: 2756)
    • Reads the cookies of Mozilla Firefox

      • AwesomeCrack.exe (PID: 3768)
    • Checks for external IP

      • AwesomeCrack.exe (PID: 3768)
    • Reads the cookies of Google Chrome

      • AwesomeCrack.exe (PID: 3768)
    • Starts CMD.EXE for commands execution

      • AwesomeCrack.exe (PID: 3768)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 4092)
    • Starts CHOICE.EXE (used to create a delay)

      • cmd.exe (PID: 4092)
    • Searches for installed software

      • AwesomeCrack.exe (PID: 3768)
  • INFO

    • Application launched itself

      • msiexec.exe (PID: 2340)
    • Creates files in the program directory

      • msiexec.exe (PID: 2340)
    • Searches for installed software

      • msiexec.exe (PID: 2340)
    • Manual execution by user

      • msiexec.exe (PID: 3428)
      • AwesomeCrack.exe (PID: 3768)
    • Low-level read access rights to disk partition

      • vssvc.exe (PID: 3252)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 2340)
    • Reads settings of System Certificates

      • AwesomeMiner.exe (PID: 2756)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2020:02:10 14:46:19
ZipCRC: 0x9e8cd91a
ZipCompressedSize: 439147
ZipUncompressedSize: 2661888
ZipFileName: AwesomeCrack.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
13
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe msiexec.exe msiexec.exe msiexec.exe no specs vssvc.exe no specs msiexec.exe no specs msiexec.exe no specs intellibreeze.maintenance.service.exe no specs awesomeminer.exe #GRANDSTEAL awesomecrack.exe cmd.exe no specs taskkill.exe no specs choice.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1676"C:\Program Files\Awesome Miner\IntelliBreeze.Maintenance.Service.exe"C:\Program Files\Awesome Miner\IntelliBreeze.Maintenance.Service.exeservices.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Description:
IntelliBreeze.Maintenance.Service
Exit code:
0
Version:
7.3.1.0
Modules
Images
c:\program files\awesome miner\intellibreeze.maintenance.service.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2340C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2432C:\Windows\system32\MsiExec.exe -Embedding 53812E962433AD5903ADE0A4A7DEDC1CC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2712C:\Windows\system32\MsiExec.exe -Embedding 29DD91240506B6C09F47632749D05EC1 M Global\MSI0000C:\Windows\system32\MsiExec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2756"C:\Program Files\Awesome Miner\AwesomeMiner.exe" C:\Program Files\Awesome Miner\AwesomeMiner.exe
MsiExec.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Awesome Miner
Exit code:
0
Version:
7.3.1.0
Modules
Images
c:\program files\awesome miner\awesomeminer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2976C:\Windows\system32\MsiExec.exe -Embedding 03C7A3D7CE868642B2A818DFA1D4B134 CC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3052taskkill /F /PID "3768"C:\Windows\system32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
3252C:\Windows\system32\vssvc.exeC:\Windows\system32\vssvc.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3420"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\AwesomeMiner7.3_patch.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
3428"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\Desktop\AwesomeMiner.msi" C:\Windows\System32\msiexec.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
2 034
Read events
1 652
Write events
370
Delete events
12

Modification events

(PID) Process:(3420) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3420) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3420) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3420) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\AwesomeMiner7.3_patch.zip
(PID) Process:(3420) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3420) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3420) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3420) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3420) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:@C:\Windows\System32\msimsg.dll,-34
Value:
Windows Installer Package
(PID) Process:(3420) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
Executable files
58
Suspicious files
5
Text files
39
Unknown types
22

Dropped files

PID
Process
Filename
Type
3420WinRAR.exeC:\Users\admin\Desktop\AwesomeMiner.msi
MD5:
SHA256:
3428msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI5FD2.tmp
MD5:
SHA256:
3428msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI7128.tmp
MD5:
SHA256:
2340msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
2340msiexec.exeC:\Windows\Installer\a8aae4.msi
MD5:
SHA256:
2340msiexec.exeC:\Users\admin\AppData\Local\Temp\~DFD3EAC9DD7FB27959.TMP
MD5:
SHA256:
2340msiexec.exeC:\Windows\Installer\MSIB3A0.tmp
MD5:
SHA256:
3252vssvc.exeC:
MD5:
SHA256:
2340msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{d7d9bd79-2f55-4b1b-acd1-e7e818853a50}_OnDiskSnapshotPropbinary
MD5:
SHA256:
2340msiexec.exeC:\Windows\Installer\a8aae5.ipibinary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
18
DNS requests
18
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2756
AwesomeMiner.exe
GET
301
104.26.11.22:80
http://www.zpool.ca/api/status
US
malicious
3768
AwesomeCrack.exe
GET
101
45.67.231.213:2012
http://45.67.231.213:2012/websocket
unknown
malicious
2756
AwesomeMiner.exe
GET
200
104.31.70.57:8080
http://api.zergpool.com:8080/api/status
US
text
38.5 Kb
shared
2756
AwesomeMiner.exe
GET
200
198.199.107.89:80
http://api.blazepool.com/s.json
US
text
11.1 Kb
unknown
2756
AwesomeMiner.exe
GET
200
54.245.13.239:80
http://blockmasters.co/api/status
US
text
6.85 Kb
unknown
2756
AwesomeMiner.exe
GET
302
198.199.107.89:80
http://api.blazepool.com/status
US
html
154 b
unknown
3768
AwesomeCrack.exe
GET
200
208.95.112.1:80
http://ip-api.com/json/
unknown
text
301 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2756
AwesomeMiner.exe
188.165.229.135:443
www.coincalculators.io
OVH SAS
FR
unknown
2756
AwesomeMiner.exe
104.26.12.88:443
whattomine.com
Cloudflare Inc
US
unknown
2756
AwesomeMiner.exe
104.27.190.128:443
miningpoolhub.com
Cloudflare Inc
US
shared
2756
AwesomeMiner.exe
104.31.70.57:8080
api.zergpool.com
Cloudflare Inc
US
shared
2756
AwesomeMiner.exe
104.26.6.30:443
nlpool.nl
Cloudflare Inc
US
suspicious
2756
AwesomeMiner.exe
104.26.11.22:80
www.zpool.ca
Cloudflare Inc
US
unknown
2756
AwesomeMiner.exe
198.199.107.89:80
api.blazepool.com
Digital Ocean, Inc.
US
unknown
2756
AwesomeMiner.exe
54.245.13.239:80
blockmasters.co
Amazon.com, Inc.
US
unknown
2756
AwesomeMiner.exe
192.241.196.35:443
www.ahashpool.com
Digital Ocean, Inc.
US
suspicious
37.187.226.185:443
www.mining-dutch.nl
OVH SAS
FR
unknown

DNS requests

Domain
IP
Reputation
www.coincalculators.io
  • 188.165.229.135
malicious
whattomine.com
  • 104.26.12.88
  • 104.26.13.88
whitelisted
5aozpdg9s2.execute-api.us-east-1.amazonaws.com
  • 13.35.253.120
  • 13.35.253.50
  • 13.35.253.109
  • 13.35.253.54
malicious
www.awesomeminer.com
  • 143.204.202.44
  • 143.204.202.52
  • 143.204.202.41
  • 143.204.202.114
malicious
miningpoolhub.com
  • 104.27.190.128
  • 104.27.191.128
whitelisted
api2.nicehash.com
  • 104.17.254.46
  • 104.17.255.46
suspicious
www.mining-dutch.nl
  • 37.187.226.185
unknown
www.zpool.ca
  • 104.26.11.22
  • 104.26.10.22
unknown
prohashing.com
  • 50.225.198.65
malicious
api.blazepool.com
  • 198.199.107.89
unknown

Threats

PID
Process
Class
Message
3768
AwesomeCrack.exe
Potential Corporate Privacy Violation
ET POLICY External IP Lookup ip-api.com
3768
AwesomeCrack.exe
Potential Corporate Privacy Violation
AV POLICY Internal Host Retrieving External IP Address (ip-api. com)
3768
AwesomeCrack.exe
A Network Trojan was detected
REMOTE [PTsecurity] Quasar.RAT IP Lookup
3 ETPRO signatures available at the full report
Process
Message
AwesomeMiner.exe
Native library pre-loader is trying to load native SQLite library "C:\Program Files\Awesome Miner\x86\SQLite.Interop.dll"...
AwesomeCrack.exe
Win32Exception: System.ComponentModel.Win32Exception (0x80004005): Element not found