File name:

Leatrix_Latency_Fix_3.03.zip

Full analysis: https://app.any.run/tasks/335e390e-beda-46a9-a93c-96704887d08f
Verdict: Malicious activity
Analysis date: May 29, 2021, 10:47:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

22A2FDAF424A9D60FE4984D383D1B44A

SHA1:

69280A064EAADD5EBC66B4914307BAF61DBDFD81

SHA256:

EAB98650CA9F4F7450E4B20C18392AC8C8D4EF9D938F4130ED1ACC97D110AFE0

SSDEEP:

98304:xd606sEGO9X+1MMvOf5eDH2y2Gv9pDRFnKjmh2Vxd45ORPcVltWGXIrEZD:xdp6sxOVM7xv9p3nB8x45OIfIAp

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • Leatrix_Latency_Fix_3.03.exe (PID: 1932)
      • SearchProtocolHost.exe (PID: 3088)
      • Leatrix_Latency_Fix_3.03.exe (PID: 1820)
    • Application was dropped or rewritten from another process

      • Leatrix_Latency_Fix_3.03.exe (PID: 1932)
      • Leatrix_Latency_Fix_3.03.exe (PID: 1472)
      • Leatrix_Latency_Fix_3.03.exe (PID: 1820)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2824)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 2824)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 2824)
    • Loads Python modules

      • Leatrix_Latency_Fix_3.03.exe (PID: 1932)
      • SearchProtocolHost.exe (PID: 3088)
      • Leatrix_Latency_Fix_3.03.exe (PID: 1820)
    • Application launched itself

      • taskmgr.exe (PID: 1428)
  • INFO

    • Manual execution by user

      • Leatrix_Latency_Fix_3.03.exe (PID: 1472)
      • Leatrix_Latency_Fix_3.03.exe (PID: 1932)
      • taskmgr.exe (PID: 1428)
      • Leatrix_Latency_Fix_3.03.exe (PID: 1820)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (36.3)

EXIF

ZIP

ZipFileName: bz2.pyd
ZipUncompressedSize: 76800
ZipCompressedSize: 36860
ZipCRC: 0x9420d1fc
ZipModifyDate: 2011:06:12 15:06:11
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
7
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe leatrix_latency_fix_3.03.exe searchprotocolhost.exe no specs leatrix_latency_fix_3.03.exe no specs leatrix_latency_fix_3.03.exe taskmgr.exe no specs taskmgr.exe

Process information

PID
CMD
Path
Indicators
Parent process
1428"C:\Windows\system32\taskmgr.exe" /4C:\Windows\system32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1472"C:\Users\admin\Desktop\Leatrix_Latency_Fix_3.03\Leatrix_Latency_Fix_3.03.exe" C:\Users\admin\Desktop\Leatrix_Latency_Fix_3.03\Leatrix_Latency_Fix_3.03.exeexplorer.exe
User:
admin
Company:
Leatrix.com
Integrity Level:
MEDIUM
Description:
Leatrix Latency Fix
Exit code:
3221226540
Version:
3.03
Modules
Images
c:\users\admin\desktop\leatrix_latency_fix_3.03\leatrix_latency_fix_3.03.exe
c:\systemroot\system32\ntdll.dll
1820"C:\Users\admin\Desktop\Leatrix_Latency_Fix_3.03\Leatrix_Latency_Fix_3.03.exe" C:\Users\admin\Desktop\Leatrix_Latency_Fix_3.03\Leatrix_Latency_Fix_3.03.exe
explorer.exe
User:
admin
Company:
Leatrix.com
Integrity Level:
HIGH
Description:
Leatrix Latency Fix
Exit code:
0
Version:
3.03
Modules
Images
c:\users\admin\desktop\leatrix_latency_fix_3.03\leatrix_latency_fix_3.03.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
1932"C:\Users\admin\Desktop\Leatrix_Latency_Fix_3.03\Leatrix_Latency_Fix_3.03.exe" C:\Users\admin\Desktop\Leatrix_Latency_Fix_3.03\Leatrix_Latency_Fix_3.03.exe
explorer.exe
User:
admin
Company:
Leatrix.com
Integrity Level:
HIGH
Description:
Leatrix Latency Fix
Exit code:
0
Version:
3.03
Modules
Images
c:\users\admin\desktop\leatrix_latency_fix_3.03\leatrix_latency_fix_3.03.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
2824"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Leatrix_Latency_Fix_3.03.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3088"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3824"C:\Windows\system32\taskmgr.exe" /1C:\Windows\system32\taskmgr.exe
taskmgr.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Task Manager
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
740
Read events
708
Write events
32
Delete events
0

Modification events

(PID) Process:(2824) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2824) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2824) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2824) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(2824) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Leatrix_Latency_Fix_3.03.zip
(PID) Process:(2824) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2824) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2824) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2824) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2824) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Leatrix_Latency_Fix_3.03
Executable files
10
Suspicious files
0
Text files
950
Unknown types
2

Dropped files

PID
Process
Filename
Type
2824WinRAR.exeC:\Users\admin\Desktop\Leatrix_Latency_Fix_3.03\Leatrix_Latency_Fix_3.03.exeexecutable
MD5:A8EFCD6182FA41B1CE97FA9ED555BC1E
SHA256:20F6BA62D21C5C1F31528E37EAD6A3CAF46B4066E416DEEA26F4937C8F6DE31E
2824WinRAR.exeC:\Users\admin\Desktop\Leatrix_Latency_Fix_3.03\bz2.pydexecutable
MD5:1CA9ECECD2C84B80996FE632627F857F
SHA256:19A62819D1ABFBE87118FF47E8E9889404331B6BD4F1A3C9B2C40D6730C6E4A8
2824WinRAR.exeC:\Users\admin\Desktop\Leatrix_Latency_Fix_3.03\select.pydexecutable
MD5:D90BF525F9F6C9C3AA6532FA6E569B4F
SHA256:7B99496B623D1BE7F69DCECDD95FB1379C1AF056FAA50611497B08BA3AC0A1E2
2824WinRAR.exeC:\Users\admin\Desktop\Leatrix_Latency_Fix_3.03\tcl\llficon.icoimage
MD5:4E9641FEF7D123CB59725E8D30C9FEA2
SHA256:0A9F7FBAA67BA1C1A3BDD8D05813F07AAB0C7AEF552F7BB3DC012FFBD4564BC1
2824WinRAR.exeC:\Users\admin\Desktop\Leatrix_Latency_Fix_3.03\unicodedata.pydexecutable
MD5:C856C31A03DC892E4F2AEE93D0BFEE44
SHA256:A1584A31ACC566862988BE6752D52E5A09312EC2234B1AAB605F2F9C4285D845
2824WinRAR.exeC:\Users\admin\Desktop\Leatrix_Latency_Fix_3.03\tcl\tcl8.5\clock.tcltext
MD5:F9F3E8061CF5CD516FC061E4DE64D8D7
SHA256:311E9725D815679A694D26257DCC4294F26EB4E8A34CA9F1C3B37963C8D4DF71
2824WinRAR.exeC:\Users\admin\Desktop\Leatrix_Latency_Fix_3.03\tcl\tcl8.5\encoding\ascii.enctext
MD5:68D69C53B4A9F0AABD60646CA7E06DAE
SHA256:294C97175FD0894093B866E73548AE660AEED0C3CC1E73867EB66E52D34C0DD2
2824WinRAR.exeC:\Users\admin\Desktop\Leatrix_Latency_Fix_3.03\tcl\tcl8.5\auto.tcltext
MD5:667AACC63FB13A5090F3724F2224A0CC
SHA256:33A3078B6FF6F34B5903EF48A8412D89E0B9687740DF156D49255222C54DE2AC
2824WinRAR.exeC:\Users\admin\Desktop\Leatrix_Latency_Fix_3.03\tcl\tcl8.5\encoding\cp1250.enctext
MD5:79ACD9BD261A252D93C9D8DDC42B8DF6
SHA256:1B42DF7E7D6B0FEB17CB0BC8D97E6CE6899492306DD880C48A39D1A2F0279004
2824WinRAR.exeC:\Users\admin\Desktop\Leatrix_Latency_Fix_3.03\tcl\tcl8.5\encoding\big5.enctext
MD5:9E67816F304FA1A8E20D2270B3A53364
SHA256:465AE2D4880B8006B1476CD60FACF676875438244C1D93A7DBE4CDE1035E745F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info