File name:

taklol.zip

Full analysis: https://app.any.run/tasks/25bf33d4-7bf2-40f5-9bfa-69ebe4b75194
Verdict: Malicious activity
Analysis date: September 30, 2020, 14:32:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
opendir
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

73A47DDC9A9EB18A72E4B81B3A05BCE2

SHA1:

3860060CEC8974948C91BBFC73F41F477D9230A4

SHA256:

EEAB2E0C590B21C7A4579B7D01E2F2543DB3F3D8B78D648F3C6380857EBF3963

SSDEEP:

98304:fy/yUb7vFeU0auScyLKZvf89PzkWt61/sq35A9+V:fy/yUb7vFeU0aufOKxfiPMsSom

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • TakLoL.exe (PID: 1720)
      • TakLoL.exe (PID: 3336)
      • pfier.exe (PID: 2808)
      • Update.exe (PID: 2816)
      • Update.exe (PID: 2844)
    • Loads dropped or rewritten executable

      • pfier.exe (PID: 2808)
      • SearchProtocolHost.exe (PID: 3844)
      • explorer.exe (PID: 328)
      • TakLoL.exe (PID: 1720)
      • ctfmon.exe (PID: 612)
      • Update.exe (PID: 2844)
    • Writes to the hosts file

      • TakLoL.exe (PID: 1720)
  • SUSPICIOUS

    • Creates files in the user directory

      • explorer.exe (PID: 328)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2852)
    • Reads Environment values

      • Update.exe (PID: 2844)
  • INFO

    • Manual execution by user

      • TakLoL.exe (PID: 3336)
      • WinRAR.exe (PID: 2852)
      • TakLoL.exe (PID: 1720)
    • Reads the hosts file

      • TakLoL.exe (PID: 1720)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2020:09:23 18:50:27
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: TakLoL/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
10
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe searchprotocolhost.exe no specs taklol.exe no specs taklol.exe pfier.exe no specs explorer.exe no specs ctfmon.exe no specs update.exe no specs update.exe

Process information

PID
CMD
Path
Indicators
Parent process
328C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\winanr.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
612C:\Windows\System32\ctfmon.exe C:\Windows\System32\ctfmon.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
CTF Loader
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ctfmon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msctfmonitor.dll
c:\windows\system32\msctf.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1720"C:\Users\admin\Desktop\TakLoL\TakLoL.exe" C:\Users\admin\Desktop\TakLoL\TakLoL.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
TakLoL Apps
Exit code:
0
Version:
1.1.1.0
Modules
Images
c:\users\admin\desktop\taklol\taklol.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2752"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\taklol.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2808"C:\Users\admin\Desktop\TakLoL\libraries\pfier\pfier.exe" C:\Users\admin\Desktop\TakLoL\libraries\pfier\pfier.exeTakLoL.exe
User:
admin
Company:
Initex
Integrity Level:
HIGH
Description:
Proxifier Portable Edition v3.42
Exit code:
0
Version:
3.42.0.1
Modules
Images
c:\users\admin\desktop\taklol\libraries\pfier\pfier.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
2816"C:\Users\admin\Desktop\TakLoL\Update.exe" C:\Users\admin\Desktop\TakLoL\Update.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
TakLoL Updater
Exit code:
3221226540
Version:
1.0.4.0
Modules
Images
c:\users\admin\desktop\taklol\update.exe
c:\systemroot\system32\ntdll.dll
2844"C:\Users\admin\Desktop\TakLoL\Update.exe" C:\Users\admin\Desktop\TakLoL\Update.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
TakLoL Updater
Exit code:
0
Version:
1.0.4.0
Modules
Images
c:\users\admin\desktop\taklol\update.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2852"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\taklol.zip" C:\Users\admin\Desktop\C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
3336"C:\Users\admin\Desktop\TakLoL\TakLoL.exe" C:\Users\admin\Desktop\TakLoL\TakLoL.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
TakLoL Apps
Exit code:
3221226540
Version:
1.1.1.0
Modules
Images
c:\users\admin\desktop\taklol\taklol.exe
c:\systemroot\system32\ntdll.dll
3844"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
5 407
Read events
5 232
Write events
175
Delete events
0

Modification events

(PID) Process:(2752) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2752) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2752) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(328) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Operation:writeName:{B41DB860-8EE4-11D2-9906-E49FADC173CA} {00000122-0000-0000-C000-000000000046} 0xFFFF
Value:
010000000000000042FE6F953697D601
(PID) Process:(328) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(328) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\OpenWithProgids
Operation:writeName:WinRAR.ZIP
Value:
(PID) Process:(328) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\OpenWithList
Operation:writeName:a
Value:
WinRAR.exe
(PID) Process:(328) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\OpenWithList
Operation:writeName:MRUList
Value:
a
(PID) Process:(328) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
Operation:writeName:9
Value:
740061006B006C006F006C002E007A00690070000000680032000000000000000000000074616B6C6F6C2E7A69702E6C6E6B00004A0008000400EFBE00000000000000002A00000000000000000000000000000000000000000000000000740061006B006C006F006C002E007A00690070002E006C006E006B0000001E000000
(PID) Process:(328) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.zip
Operation:writeName:0
Value:
740061006B006C006F006C002E007A00690070000000680032000000000000000000000074616B6C6F6C2E7A69702E6C6E6B00004A0008000400EFBE00000000000000002A00000000000000000000000000000000000000000000000000740061006B006C006F006C002E007A00690070002E006C006E006B0000001E000000
Executable files
6
Suspicious files
0
Text files
73
Unknown types
3

Dropped files

PID
Process
Filename
Type
328explorer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-msautomaticdestinations-ms
MD5:
SHA256:
328explorer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\290532160612e071.automaticDestinations-msautomaticdestinations-ms
MD5:
SHA256:
328explorer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\taklol.zip.lnklnk
MD5:
SHA256:
2852WinRAR.exeC:\Users\admin\Desktop\TakLoL\TakLoL.exeexecutable
MD5:
SHA256:
2852WinRAR.exeC:\Users\admin\Desktop\TakLoL\Update.exeexecutable
MD5:
SHA256:
1720TakLoL.exeC:\Users\admin\Desktop\TakLoL\LData.cfgtext
MD5:
SHA256:
2852WinRAR.exeC:\Users\admin\Desktop\TakLoL\libraries\pfier\Settings.initext
MD5:
SHA256:
2852WinRAR.exeC:\Users\admin\Desktop\TakLoL\libraries\pfier\PrxDrvPE.dllexecutable
MD5:D3DA1003323423DA89AF2C83E5E2B40A
SHA256:44243F0D0102D654C5CAD1AC3826B52DA9454D4AF99D9A417CEB6AE4DDDA71F0
2852WinRAR.exeC:\Users\admin\Desktop\TakLoL\libraries\pfier\PrxDrvPE64.dllexecutable
MD5:77F0642BCD7A97A068C0AFE70BE22F03
SHA256:E109011F96919D968164DE6957B9A75E87A167AFA961855AF7C291E8DE475735
1720TakLoL.exeC:\Windows\System32\drivers\etc\hoststext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
3
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1720
TakLoL.exe
POST
200
104.24.112.121:80
http://taklol.taklol.ir/update/getlast5
US
text
3.68 Kb
suspicious
1720
TakLoL.exe
POST
200
104.24.113.121:80
http://taklol.ir/update/getlast5
US
text
3.68 Kb
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1720
TakLoL.exe
104.24.113.121:80
taklol.ir
Cloudflare Inc
US
shared
1720
TakLoL.exe
104.24.112.121:80
taklol.ir
Cloudflare Inc
US
shared
2844
Update.exe
172.67.146.87:80
taklol.ir
US
suspicious

DNS requests

Domain
IP
Reputation
taklol.ir
  • 104.24.113.121
  • 104.24.112.121
  • 172.67.146.87
suspicious
taklol.taklol.ir
  • 104.24.112.121
  • 172.67.146.87
  • 104.24.113.121
suspicious
www.google.com
  • 172.217.22.100
malicious

Threats

No threats detected
No debug info