download:

TOOL%20ALL%20IN%20ONE%20v1.0.9.4.zip

Full analysis: https://app.any.run/tasks/6fe322be-296a-4e89-a1b4-af29a64998c7
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: July 13, 2020, 07:09:58
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
floxif
loader
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

3FBC2A72BD89929C27E3BFA8BB070FAB

SHA1:

CBB6E766E1AAB11C7DA12A03678724A096A6FF47

SHA256:

F2F4FA18368443C4EC441C1C4F27A0C2CCCD0443BAEA3031DCC247B04D7479C5

SSDEEP:

393216:OBBQmTrVZnr07j7Wek0SNMHimYPCYnbPQOqjrATSdGjamKOXESrmvL4dy+66:uBoH7ONMXYP4IOdDOXE9ky+j

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 1632)
      • adb.exe (PID: 2780)
      • adb.exe (PID: 4052)
      • fastboot.exe (PID: 2664)
      • adb.exe (PID: 2828)
      • fastboot.exe (PID: 3532)
      • adb.exe (PID: 2408)
      • adb.exe (PID: 2208)
      • fastboot.exe (PID: 2616)
      • adb.exe (PID: 3280)
      • adb.exe (PID: 2472)
      • adb.exe (PID: 1876)
      • adb.exe (PID: 3800)
      • adb.exe (PID: 4016)
    • Application was dropped or rewritten from another process

      • fastboot.exe (PID: 2664)
      • adb.exe (PID: 2780)
      • adb.exe (PID: 4052)
      • TOOL_ALL_IN_ONE.exe (PID: 1600)
      • adb.exe (PID: 2208)
      • adb.exe (PID: 2828)
      • Updater_TOOL_ALL_IN_ONE.exe (PID: 2284)
      • TOOL_ALL_IN_ONE.exe (PID: 3352)
      • fastboot.exe (PID: 3532)
      • adb.exe (PID: 2408)
      • fastboot.exe (PID: 2616)
      • adb.exe (PID: 3280)
      • adb.exe (PID: 4016)
      • adb.exe (PID: 1876)
      • adb.exe (PID: 2472)
      • adb.exe (PID: 3800)
    • Changes the autorun value in the registry

      • adb.exe (PID: 2780)
    • FLOXIF was detected

      • adb.exe (PID: 2780)
      • adb.exe (PID: 4052)
    • Changes AppInit_DLLs value (autorun option)

      • adb.exe (PID: 2780)
    • Connects to CnC server

      • adb.exe (PID: 4052)
      • adb.exe (PID: 2780)
    • Downloads executable files from the Internet

      • TOOL_ALL_IN_ONE.exe (PID: 1600)
      • Updater_TOOL_ALL_IN_ONE.exe (PID: 2284)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • fastboot.exe (PID: 2664)
      • WinRAR.exe (PID: 3656)
      • TOOL_ALL_IN_ONE.exe (PID: 1600)
      • Updater_TOOL_ALL_IN_ONE.exe (PID: 2284)
      • TOOL_ALL_IN_ONE.exe (PID: 3352)
    • Starts CMD.EXE for commands execution

      • TOOL_ALL_IN_ONE.exe (PID: 1600)
      • TOOL_ALL_IN_ONE.exe (PID: 3352)
    • Reads Internet Cache Settings

      • adb.exe (PID: 4052)
      • adb.exe (PID: 2780)
    • Application launched itself

      • adb.exe (PID: 4052)
      • adb.exe (PID: 1876)
  • INFO

    • Manual execution by user

      • TOOL_ALL_IN_ONE.exe (PID: 1600)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0808
ZipCompression: Deflated
ZipModifyDate: 2020:07:13 14:58:01
ZipCRC: 0x00000000
ZipCompressedSize: 2
ZipUncompressedSize: -
ZipFileName: TWRP_recovery/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
71
Monitored processes
26
Malicious processes
16
Suspicious processes
6

Behavior graph

Click at the process to see the details
start drop and start drop and start winrar.exe searchprotocolhost.exe no specs tool_all_in_one.exe cmd.exe no specs fastboot.exe cmd.exe no specs #FLOXIF adb.exe #FLOXIF adb.exe adb.exe updater_tool_all_in_one.exe tool_all_in_one.exe cmd.exe no specs fastboot.exe no specs cmd.exe no specs adb.exe adb.exe cmd.exe no specs fastboot.exe no specs cmd.exe no specs adb.exe adb.exe cmd.exe no specs adb.exe cmd.exe no specs adb.exe adb.exe

Process information

PID
CMD
Path
Indicators
Parent process
832cmd.exe /cadb kill-server C:\Windows\system32\cmd.exeTOOL_ALL_IN_ONE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1600"C:\Users\admin\Desktop\TOOL_ALL_IN_ONE.exe" C:\Users\admin\Desktop\TOOL_ALL_IN_ONE.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
TOOL_ALL_IN_ONE
Exit code:
0
Version:
1.1.0.3
Modules
Images
c:\users\admin\desktop\tool_all_in_one.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1632"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1876adb start-server C:\Users\admin\Desktop\adb.exe
cmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\adb.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\adbwinapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2052cmd.exe /cfastboot devices > fastdet & echo 1 >> fastdet C:\Windows\system32\cmd.exeTOOL_ALL_IN_ONE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2208adb devices C:\Users\admin\Desktop\adb.exe
cmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\adb.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\adbwinapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2284"C:\Users\admin\Desktop\Updater_TOOL_ALL_IN_ONE.exe" C:\Users\admin\Desktop\Updater_TOOL_ALL_IN_ONE.exe
TOOL_ALL_IN_ONE.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Updater_TOOL_ALL_IN_ONE
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\updater_tool_all_in_one.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2408adb start-server C:\Users\admin\Desktop\adb.exe
cmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\adb.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\adbwinapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2472adb kill-server C:\Users\admin\Desktop\adb.exe
cmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\adb.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\adbwinapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2616fastboot devices C:\Users\admin\Desktop\fastboot.execmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\fastboot.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\adbwinapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
1 191
Read events
1 104
Write events
87
Delete events
0

Modification events

(PID) Process:(3656) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3656) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3656) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3656) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(3656) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\e2c0d8de-d072-4846-a34f-0f5c1a836dad.zip
(PID) Process:(3656) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3656) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3656) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3656) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3656) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
35
Suspicious files
3
Text files
15
Unknown types
2

Dropped files

PID
Process
Filename
Type
3656WinRAR.exeC:\Users\admin\Desktop\screenfoldercheck
MD5:
SHA256:
3656WinRAR.exeC:\Users\admin\Desktop\Drivers\Drivers.zipcompressed
MD5:
SHA256:
3656WinRAR.exeC:\Users\admin\Desktop\Drivers\amd64\NOTICE.txttext
MD5:EA7F2158B930BAF2C0FE799566489716
SHA256:A19B767B9DDDA7306C78232E4A223D0BA966471B74DCE3C0C995307CAB5BF7B7
3656WinRAR.exeC:\Users\admin\Desktop\source.propertiestext
MD5:
SHA256:
3656WinRAR.exeC:\Users\admin\Desktop\TOOL_ALL_IN_ONE.exeexecutable
MD5:
SHA256:
3656WinRAR.exeC:\Users\admin\Desktop\mke2fs.exeexecutable
MD5:
SHA256:
3656WinRAR.exeC:\Users\admin\Desktop\Updater_TOOL_ALL_IN_ONE.exeexecutable
MD5:
SHA256:
3656WinRAR.exeC:\Users\admin\Desktop\sqlite3.exeexecutable
MD5:
SHA256:
3656WinRAR.exeC:\Users\admin\Desktop\Drivers\androidwinusba64.catcat
MD5:B83F9FA084F11007C7E6C668E6FA9E54
SHA256:8F3F15BAEAF50AE7388562BE0303F5AC7EE3CB255448A24E3D33E1F094E0680E
3656WinRAR.exeC:\Users\admin\Desktop\Drivers\amd64\winusbcoinstaller2.dllexecutable
MD5:246900CE6474718730ECD4F873234CF5
SHA256:981A17EFFDDBC20377512DDAEC9F22C2B7067E17A3E2A8CCF82BB7BB7B2420B6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
13
TCP/UDP connections
13
DNS requests
6
Threats
19

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1600
TOOL_ALL_IN_ONE.exe
GET
200
138.201.61.244:80
http://toolone.altervista.org/AFFiles/AFVersion.txt
DE
text
6 b
suspicious
2284
Updater_TOOL_ALL_IN_ONE.exe
GET
200
138.201.61.244:80
http://toolone.altervista.org/TOOLALLINONE/TOOL_ALL_IN_ONE.exe
DE
executable
3.45 Mb
suspicious
3352
TOOL_ALL_IN_ONE.exe
GET
200
138.201.61.244:80
http://toolone.altervista.org/AFFiles/AFFiles.zip
DE
compressed
3.00 Mb
suspicious
3352
TOOL_ALL_IN_ONE.exe
GET
200
138.201.61.244:80
http://toolone.altervista.org/AFFiles/AFVersion.txt
DE
text
6 b
suspicious
1600
TOOL_ALL_IN_ONE.exe
GET
200
138.201.61.244:80
http://toolone.altervista.org/TOOLALLINONE2/Version.txt
DE
text
7 b
suspicious
4052
adb.exe
GET
403
104.200.22.130:80
http://www.aieov.com/logo.gif
US
html
175 b
malicious
2780
adb.exe
GET
403
104.200.22.130:80
http://www.aieov.com/logo.gif
US
html
175 b
malicious
2780
adb.exe
GET
403
104.200.22.130:80
http://www.aieov.com/logo.gif
US
html
175 b
malicious
1600
TOOL_ALL_IN_ONE.exe
GET
200
138.201.61.244:80
http://toolone.altervista.org/TOOLALLINONE2/Updater_TOOL_ALL_IN_ONE.exe
DE
executable
1.08 Mb
suspicious
2780
adb.exe
GET
403
104.200.22.130:80
http://www.aieov.com/logo.gif
US
html
175 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1600
TOOL_ALL_IN_ONE.exe
138.201.61.244:80
toolone.altervista.org
Hetzner Online GmbH
DE
suspicious
104.200.22.130:80
www.aieov.com
Linode, LLC
US
malicious
2780
adb.exe
104.200.22.130:80
www.aieov.com
Linode, LLC
US
malicious
3352
TOOL_ALL_IN_ONE.exe
138.201.61.244:80
toolone.altervista.org
Hetzner Online GmbH
DE
suspicious
2284
Updater_TOOL_ALL_IN_ONE.exe
138.201.61.244:80
toolone.altervista.org
Hetzner Online GmbH
DE
suspicious

DNS requests

Domain
IP
Reputation
www.google.it
  • 216.58.205.227
whitelisted
toolone.altervista.org
  • 138.201.61.244
suspicious
5isohu.com
whitelisted
www.aieov.com
  • 104.200.22.130
  • 104.200.23.95
malicious
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

PID
Process
Class
Message
4052
adb.exe
A Network Trojan was detected
MALWARE [PTsecurity] Win32.Floxif.A
2780
adb.exe
A Network Trojan was detected
MALWARE [PTsecurity] Win32.Floxif.A
2780
adb.exe
A Network Trojan was detected
MALWARE [PTsecurity] Win32.Floxif.A
2780
adb.exe
A Network Trojan was detected
MALWARE [PTsecurity] Win32.Floxif.A
2780
adb.exe
A Network Trojan was detected
MALWARE [PTsecurity] Win32.Floxif.A
1600
TOOL_ALL_IN_ONE.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
1600
TOOL_ALL_IN_ONE.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
2284
Updater_TOOL_ALL_IN_ONE.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2284
Updater_TOOL_ALL_IN_ONE.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
2780
adb.exe
A Network Trojan was detected
MALWARE [PTsecurity] Win32.Floxif.A
8 ETPRO signatures available at the full report
No debug info