File name:

HQ Proxy Grabber V5.0.5.rar

Full analysis: https://app.any.run/tasks/30c4a210-cf21-4b52-89d6-4f0fe464c956
Verdict: Malicious activity
Analysis date: October 24, 2019, 22:38:18
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

528196550F9E092BD19FDB7B766758C1

SHA1:

A052CA17E214F64229A388C3A592C83A831A6634

SHA256:

EB273DF820ECB248A69954444E4164CEDCB621122E5F3EF3D95C155C2F2C648F

SSDEEP:

6144:N8h2ayiD9r6GUZFGJJTKco3hlpsZDsU8UDhx+Lw2Hq/+jgRc6yTphZ+888KA7r:NzWxTUKyGZDsU/2LU/MgRlYphZ88KA7r

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • HQ Proxy Grabber V5.0.5.exe (PID: 1756)
      • SearchProtocolHost.exe (PID: 3444)
    • Application was dropped or rewritten from another process

      • HQ Proxy Grabber V5.0.5.exe (PID: 1756)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 436)
  • INFO

    • Manual execution by user

      • HQ Proxy Grabber V5.0.5.exe (PID: 1756)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 121053
UncompressedSize: 176128
OperatingSystem: Win32
ModifyDate: 2019:06:15 00:39:17
PackingMethod: Normal
ArchivedFileName: HQ Proxy Grabber V5.0.5\HQ Proxy Grabber V5.0.5.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs hq proxy grabber v5.0.5.exe

Process information

PID
CMD
Path
Indicators
Parent process
436"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\HQ Proxy Grabber V5.0.5.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1756"C:\Users\admin\Desktop\HQ Proxy Grabber V5.0.5\HQ Proxy Grabber V5.0.5.exe" C:\Users\admin\Desktop\HQ Proxy Grabber V5.0.5\HQ Proxy Grabber V5.0.5.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Grabber Checker Proxy 1.0
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\hq proxy grabber v5.0.5\hq proxy grabber v5.0.5.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3444"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
842
Read events
799
Write events
43
Delete events
0

Modification events

(PID) Process:(436) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(436) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(436) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(436) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\HQ Proxy Grabber V5.0.5.rar
(PID) Process:(436) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(436) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(436) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(436) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(436) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
(PID) Process:(3444) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
5
Suspicious files
4
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
1756HQ Proxy Grabber V5.0.5.exeC:\Users\admin\AppData\Local\Temp\Cab47A.tmp
MD5:
SHA256:
1756HQ Proxy Grabber V5.0.5.exeC:\Users\admin\AppData\Local\Temp\Tar47B.tmp
MD5:
SHA256:
1756HQ Proxy Grabber V5.0.5.exeC:\Users\admin\AppData\Local\Temp\Cab48C.tmp
MD5:
SHA256:
1756HQ Proxy Grabber V5.0.5.exeC:\Users\admin\AppData\Local\Temp\Tar48D.tmp
MD5:
SHA256:
1756HQ Proxy Grabber V5.0.5.exeC:\Users\admin\AppData\Local\Temp\Cab568.tmp
MD5:
SHA256:
1756HQ Proxy Grabber V5.0.5.exeC:\Users\admin\AppData\Local\Temp\Tar569.tmp
MD5:
SHA256:
1756HQ Proxy Grabber V5.0.5.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015binary
MD5:
SHA256:
436WinRAR.exeC:\Users\admin\Desktop\HQ Proxy Grabber V5.0.5\System.Reactive.Core.dllexecutable
MD5:0774852BCA4A8A4F66E7029EE2E2E846
SHA256:E020A6BA66944879DAB22E77C728FA079DAEC0A3D9D4EB995BAFB73B5528B10F
436WinRAR.exeC:\Users\admin\Desktop\HQ Proxy Grabber V5.0.5\Read before using.txttext
MD5:B6A9D39F24FCD3854E004ECC3506BCA5
SHA256:E60AC0DF857E1AF1CCB5FBE9C060AE6BEDA88B7F7B734A59E9C31FB36CE920B6
436WinRAR.exeC:\Users\admin\Desktop\HQ Proxy Grabber V5.0.5\HQ Proxy Grabber V5.0.5.exeexecutable
MD5:AAE882B888A9FE649E5B0EB9F5D6F5A9
SHA256:97B72AC00F8A333035281CA470F837DD8420A4E79AD53E37BD6FBF8854BEE0EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
291
TCP/UDP connections
368
DNS requests
74
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1756
HQ Proxy Grabber V5.0.5.exe
GET
302
103.224.212.222:80
http://txt.proxyspy.net/proxy.txt
AU
malicious
1756
HQ Proxy Grabber V5.0.5.exe
GET
302
72.52.179.174:80
http://getproxy.jp/en/?area=en
US
malicious
1756
HQ Proxy Grabber V5.0.5.exe
GET
172.217.18.161:80
http://sslproxies24.blogspot.com/
US
whitelisted
1756
HQ Proxy Grabber V5.0.5.exe
GET
72.52.179.174:80
http://getproxy.jp/en/default/4
US
malicious
1756
HQ Proxy Grabber V5.0.5.exe
GET
89.208.212.2:80
http://aliveproxy.com/proxy-list-port-81/
RU
suspicious
1756
HQ Proxy Grabber V5.0.5.exe
GET
200
89.208.212.2:80
http://atomintersoft.com/transparent_proxy_list
RU
html
18.8 Kb
malicious
1756
HQ Proxy Grabber V5.0.5.exe
GET
200
89.208.212.2:80
http://atomintersoft.com/products/alive-proxy/proxy-list/3128
RU
html
18.4 Kb
malicious
1756
HQ Proxy Grabber V5.0.5.exe
GET
200
109.201.133.56:80
http://proxylistchecker.org/proxylists.php?t=&p=15
NL
html
498 b
suspicious
1756
HQ Proxy Grabber V5.0.5.exe
GET
200
172.217.23.179:80
http://www.sslproxies24.top/
US
html
56.0 Kb
whitelisted
1756
HQ Proxy Grabber V5.0.5.exe
GET
301
92.48.97.11:80
http://samair.ru/proxy/proxy-02.htm
GB
html
241 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1756
HQ Proxy Grabber V5.0.5.exe
104.18.50.219:443
orca.tech
Cloudflare Inc
US
shared
1756
HQ Proxy Grabber V5.0.5.exe
104.27.152.82:443
openinternetaccess.com
Cloudflare Inc
US
unknown
1756
HQ Proxy Grabber V5.0.5.exe
138.201.122.249:80
notan.h1.ru
Hetzner Online GmbH
DE
malicious
1756
HQ Proxy Grabber V5.0.5.exe
92.48.97.11:80
samair.ru
Simply Transit Ltd
GB
malicious
1756
HQ Proxy Grabber V5.0.5.exe
89.208.212.2:80
aliveproxy.com
JSC Digital Network
RU
suspicious
1756
HQ Proxy Grabber V5.0.5.exe
103.224.212.222:80
txt.proxyspy.net
Trellian Pty. Limited
AU
malicious
1756
HQ Proxy Grabber V5.0.5.exe
72.52.179.174:80
getproxy.jp
Liquid Web, L.L.C
US
malicious
1756
HQ Proxy Grabber V5.0.5.exe
172.217.18.161:80
sslproxies24.blogspot.com
Google Inc.
US
whitelisted
1756
HQ Proxy Grabber V5.0.5.exe
104.24.117.90:80
my-proxy.com
Cloudflare Inc
US
shared
1756
HQ Proxy Grabber V5.0.5.exe
78.41.204.28:80
proxylistchecker.org
Snel.com B.V.
NL
malicious

DNS requests

Domain
IP
Reputation
orca.tech
  • 104.18.50.219
  • 104.18.51.219
malicious
openinternetaccess.com
  • 104.27.152.82
  • 104.27.153.82
unknown
getproxy.jp
  • 72.52.179.174
malicious
notan.h1.ru
  • 138.201.122.249
malicious
aliveproxy.com
  • 89.208.212.2
suspicious
sslproxies24.blogspot.com
  • 172.217.18.161
whitelisted
samair.ru
  • 92.48.97.11
malicious
proxylistchecker.org
  • 109.201.133.56
  • 78.41.204.28
suspicious
my-proxy.com
  • 104.24.117.90
  • 104.24.116.90
whitelisted
atomintersoft.com
  • 89.208.212.2
malicious

Threats

PID
Process
Class
Message
1080
svchost.exe
Potentially Bad Traffic
ET DNS Query to a *.top domain - Likely Hostile
1756
HQ Proxy Grabber V5.0.5.exe
Potentially Bad Traffic
ET INFO HTTP Request to a *.top domain
1756
HQ Proxy Grabber V5.0.5.exe
Potential Corporate Privacy Violation
POLICY [PTsecurity] External IP Address Check
No debug info