| File name: | HQ Proxy Grabber V5.0.5.rar |
| Full analysis: | https://app.any.run/tasks/30c4a210-cf21-4b52-89d6-4f0fe464c956 |
| Verdict: | Malicious activity |
| Analysis date: | October 24, 2019, 22:38:18 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32 |
| MD5: | 528196550F9E092BD19FDB7B766758C1 |
| SHA1: | A052CA17E214F64229A388C3A592C83A831A6634 |
| SHA256: | EB273DF820ECB248A69954444E4164CEDCB621122E5F3EF3D95C155C2F2C648F |
| SSDEEP: | 6144:N8h2ayiD9r6GUZFGJJTKco3hlpsZDsU8UDhx+Lw2Hq/+jgRc6yTphZ+888KA7r:NzWxTUKyGZDsU/2LU/MgRlYphZ88KA7r |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| CompressedSize: | 121053 |
|---|---|
| UncompressedSize: | 176128 |
| OperatingSystem: | Win32 |
| ModifyDate: | 2019:06:15 00:39:17 |
| PackingMethod: | Normal |
| ArchivedFileName: | HQ Proxy Grabber V5.0.5\HQ Proxy Grabber V5.0.5.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 436 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\HQ Proxy Grabber V5.0.5.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 1756 | "C:\Users\admin\Desktop\HQ Proxy Grabber V5.0.5\HQ Proxy Grabber V5.0.5.exe" | C:\Users\admin\Desktop\HQ Proxy Grabber V5.0.5\HQ Proxy Grabber V5.0.5.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Grabber Checker Proxy 1.0 Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 3444 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\System32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (436) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (436) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (436) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (436) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\HQ Proxy Grabber V5.0.5.rar | |||
| (PID) Process: | (436) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (436) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (436) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (436) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (436) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop | |||
| (PID) Process: | (3444) SearchProtocolHost.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1756 | HQ Proxy Grabber V5.0.5.exe | C:\Users\admin\AppData\Local\Temp\Cab47A.tmp | — | |
MD5:— | SHA256:— | |||
| 1756 | HQ Proxy Grabber V5.0.5.exe | C:\Users\admin\AppData\Local\Temp\Tar47B.tmp | — | |
MD5:— | SHA256:— | |||
| 1756 | HQ Proxy Grabber V5.0.5.exe | C:\Users\admin\AppData\Local\Temp\Cab48C.tmp | — | |
MD5:— | SHA256:— | |||
| 1756 | HQ Proxy Grabber V5.0.5.exe | C:\Users\admin\AppData\Local\Temp\Tar48D.tmp | — | |
MD5:— | SHA256:— | |||
| 1756 | HQ Proxy Grabber V5.0.5.exe | C:\Users\admin\AppData\Local\Temp\Cab568.tmp | — | |
MD5:— | SHA256:— | |||
| 1756 | HQ Proxy Grabber V5.0.5.exe | C:\Users\admin\AppData\Local\Temp\Tar569.tmp | — | |
MD5:— | SHA256:— | |||
| 1756 | HQ Proxy Grabber V5.0.5.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 | binary | |
MD5:— | SHA256:— | |||
| 436 | WinRAR.exe | C:\Users\admin\Desktop\HQ Proxy Grabber V5.0.5\System.Reactive.Core.dll | executable | |
MD5:0774852BCA4A8A4F66E7029EE2E2E846 | SHA256:E020A6BA66944879DAB22E77C728FA079DAEC0A3D9D4EB995BAFB73B5528B10F | |||
| 436 | WinRAR.exe | C:\Users\admin\Desktop\HQ Proxy Grabber V5.0.5\Read before using.txt | text | |
MD5:B6A9D39F24FCD3854E004ECC3506BCA5 | SHA256:E60AC0DF857E1AF1CCB5FBE9C060AE6BEDA88B7F7B734A59E9C31FB36CE920B6 | |||
| 436 | WinRAR.exe | C:\Users\admin\Desktop\HQ Proxy Grabber V5.0.5\HQ Proxy Grabber V5.0.5.exe | executable | |
MD5:AAE882B888A9FE649E5B0EB9F5D6F5A9 | SHA256:97B72AC00F8A333035281CA470F837DD8420A4E79AD53E37BD6FBF8854BEE0EB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1756 | HQ Proxy Grabber V5.0.5.exe | GET | 302 | 103.224.212.222:80 | http://txt.proxyspy.net/proxy.txt | AU | — | — | malicious |
1756 | HQ Proxy Grabber V5.0.5.exe | GET | 302 | 72.52.179.174:80 | http://getproxy.jp/en/?area=en | US | — | — | malicious |
1756 | HQ Proxy Grabber V5.0.5.exe | GET | — | 172.217.18.161:80 | http://sslproxies24.blogspot.com/ | US | — | — | whitelisted |
1756 | HQ Proxy Grabber V5.0.5.exe | GET | — | 72.52.179.174:80 | http://getproxy.jp/en/default/4 | US | — | — | malicious |
1756 | HQ Proxy Grabber V5.0.5.exe | GET | — | 89.208.212.2:80 | http://aliveproxy.com/proxy-list-port-81/ | RU | — | — | suspicious |
1756 | HQ Proxy Grabber V5.0.5.exe | GET | 200 | 89.208.212.2:80 | http://atomintersoft.com/transparent_proxy_list | RU | html | 18.8 Kb | malicious |
1756 | HQ Proxy Grabber V5.0.5.exe | GET | 200 | 89.208.212.2:80 | http://atomintersoft.com/products/alive-proxy/proxy-list/3128 | RU | html | 18.4 Kb | malicious |
1756 | HQ Proxy Grabber V5.0.5.exe | GET | 200 | 109.201.133.56:80 | http://proxylistchecker.org/proxylists.php?t=&p=15 | NL | html | 498 b | suspicious |
1756 | HQ Proxy Grabber V5.0.5.exe | GET | 200 | 172.217.23.179:80 | http://www.sslproxies24.top/ | US | html | 56.0 Kb | whitelisted |
1756 | HQ Proxy Grabber V5.0.5.exe | GET | 301 | 92.48.97.11:80 | http://samair.ru/proxy/proxy-02.htm | GB | html | 241 b | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1756 | HQ Proxy Grabber V5.0.5.exe | 104.18.50.219:443 | orca.tech | Cloudflare Inc | US | shared |
1756 | HQ Proxy Grabber V5.0.5.exe | 104.27.152.82:443 | openinternetaccess.com | Cloudflare Inc | US | unknown |
1756 | HQ Proxy Grabber V5.0.5.exe | 138.201.122.249:80 | notan.h1.ru | Hetzner Online GmbH | DE | malicious |
1756 | HQ Proxy Grabber V5.0.5.exe | 92.48.97.11:80 | samair.ru | Simply Transit Ltd | GB | malicious |
1756 | HQ Proxy Grabber V5.0.5.exe | 89.208.212.2:80 | aliveproxy.com | JSC Digital Network | RU | suspicious |
1756 | HQ Proxy Grabber V5.0.5.exe | 103.224.212.222:80 | txt.proxyspy.net | Trellian Pty. Limited | AU | malicious |
1756 | HQ Proxy Grabber V5.0.5.exe | 72.52.179.174:80 | getproxy.jp | Liquid Web, L.L.C | US | malicious |
1756 | HQ Proxy Grabber V5.0.5.exe | 172.217.18.161:80 | sslproxies24.blogspot.com | Google Inc. | US | whitelisted |
1756 | HQ Proxy Grabber V5.0.5.exe | 104.24.117.90:80 | my-proxy.com | Cloudflare Inc | US | shared |
1756 | HQ Proxy Grabber V5.0.5.exe | 78.41.204.28:80 | proxylistchecker.org | Snel.com B.V. | NL | malicious |
Domain | IP | Reputation |
|---|---|---|
orca.tech |
| malicious |
openinternetaccess.com |
| unknown |
getproxy.jp |
| malicious |
notan.h1.ru |
| malicious |
aliveproxy.com |
| suspicious |
sslproxies24.blogspot.com |
| whitelisted |
samair.ru |
| malicious |
proxylistchecker.org |
| suspicious |
my-proxy.com |
| whitelisted |
atomintersoft.com |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Potentially Bad Traffic | ET DNS Query to a *.top domain - Likely Hostile |
1756 | HQ Proxy Grabber V5.0.5.exe | Potentially Bad Traffic | ET INFO HTTP Request to a *.top domain |
1756 | HQ Proxy Grabber V5.0.5.exe | Potential Corporate Privacy Violation | POLICY [PTsecurity] External IP Address Check |