File name:

Proxo_V1.4.rar

Full analysis: https://app.any.run/tasks/4dd06e40-910b-4aee-b634-a3ef47baaeae
Verdict: Malicious activity
Analysis date: January 25, 2019, 13:36:12
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

4C5CB122D5F29FC81AB4CBEE8EEEBB69

SHA1:

559A2640F4BC0A9F7E2B8C5D479857986B5449D9

SHA256:

F4AE7E42FA8389709CFE8701C9E04D35E388D0D8A8C96E2B6153C3775423E5C2

SSDEEP:

24576:swPbJ1mg6t5fIH76f1sBwieH66xDC/m9OEdlEw8960q4cugsN9:swPbJiIb6dsB+VDBpsI9ud9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • Proxo.exe (PID: 1644)
      • Proxo.exe (PID: 3520)
      • Proxo Injector.exe (PID: 2072)
    • Application was dropped or rewritten from another process

      • Proxo.exe (PID: 3520)
      • Lag Switch.exe (PID: 2236)
      • Multiple_ROBLOX.exe (PID: 3300)
      • Proxo Injector.exe (PID: 2072)
      • Proxo.exe (PID: 1644)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3000)
    • Reads Environment values

      • Lag Switch.exe (PID: 2236)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • WinRAR.exe (PID: 3000)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
6
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
drop and start drop and start drop and start drop and start drop and start start winrar.exe proxo.exe no specs proxo injector.exe no specs lag switch.exe multiple_roblox.exe no specs proxo.exe

Process information

PID
CMD
Path
Indicators
Parent process
1644"C:\Users\admin\AppData\Local\Temp\Rar$EXa3000.41637\Proxo V1.4\Proxo.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3000.41637\Proxo V1.4\Proxo.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Proxo
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3000.41637\proxo v1.4\proxo.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2072"C:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40660\Proxo V1.4\Proxo Injector.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40660\Proxo V1.4\Proxo Injector.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
ProxoInstaller
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3000.40660\proxo v1.4\proxo injector.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2236"C:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40854\Proxo V1.4\Lag Switch.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40854\Proxo V1.4\Lag Switch.exe
WinRAR.exe
User:
admin
Company:
JonathonPowell
Integrity Level:
MEDIUM
Description:
Lag Switch
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3000.40854\proxo v1.4\lag switch.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3000"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Proxo_V1.4.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3300"C:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40983\Proxo V1.4\Multiple_ROBLOX.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40983\Proxo V1.4\Multiple_ROBLOX.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Multiple ROBLOX
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3000.40983\proxo v1.4\multiple_roblox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3520"C:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40102\Proxo V1.4\Proxo.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40102\Proxo V1.4\Proxo.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Proxo
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3000.40102\proxo v1.4\proxo.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
526
Read events
469
Write events
57
Delete events
0

Modification events

(PID) Process:(3000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3000) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Proxo_V1.4.rar
(PID) Process:(3000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
40
Suspicious files
0
Text files
45
Unknown types
0

Dropped files

PID
Process
Filename
Type
3000WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40102\Proxo V1.4\Proxo Injector.exeexecutable
MD5:
SHA256:
3000WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40102\Proxo V1.4\Proxo.exeexecutable
MD5:
SHA256:
3000WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40102\Proxo V1.4\Scripts\Admin_for_auto_rap_suxxxx.txttext
MD5:
SHA256:
3000WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40102\Proxo V1.4\Scripts\HttpGet RoseHub.txttext
MD5:
SHA256:
3000WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40102\Proxo V1.4\WeAreDevs_API.dllexecutable
MD5:
SHA256:
3000WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40102\Proxo V1.4\Scripts\[FE] Dab.txttext
MD5:07B9E2FF159D00759B0AA0532762E623
SHA256:835D33BB4C894DD8BBD23F37533B24B6F0D66B5FA4D732F6B917265493F7F787
3000WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40102\Proxo V1.4\Lag Switch.exeexecutable
MD5:68EC8BB5B181D5D2506FF9F9476087A0
SHA256:B6AC3F99FE3A7731B91EF8DC1B27BE56CBB219FDE1461327177AB0506615FF73
3000WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40102\Proxo V1.4\Scripts\[FE] Fling (R15).txttext
MD5:F43F24448C0C79AB66E45BAE4348CD74
SHA256:E5284714000A61048AC7828CD84F953EA68E01FC65279C5A88936374BD4FF0E7
3000WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40102\Proxo V1.4\Multiple_ROBLOX.exeexecutable
MD5:AED655395747A6602479F6032D3C099F
SHA256:3D6123DC6FFBD1A11D73229988203052809BD17617B24A034C1122C8F4983DB4
3000WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40102\Proxo V1.4\Scripts\FE Animation.txttext
MD5:C5D6F37EA7A5742663AA3C53DCBCA2A2
SHA256:2906C02E9B72943D86312615D4C004AF56BF3556A339C19F1ED3D70446F95DAC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
3
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2236
Lag Switch.exe
GET
301
104.24.14.43:80
http://www.wearedevs.net/Assets/softwaredetails.txt
US
suspicious
2236
Lag Switch.exe
GET
301
104.24.14.43:80
http://www.wearedevs.net/Assets/softwaredetails.txt
US
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2236
Lag Switch.exe
104.24.14.43:443
www.wearedevs.net
Cloudflare Inc
US
shared
1644
Proxo.exe
104.27.135.31:443
anton.to
Cloudflare Inc
US
shared
2236
Lag Switch.exe
104.24.14.43:80
www.wearedevs.net
Cloudflare Inc
US
shared

DNS requests

Domain
IP
Reputation
www.wearedevs.net
  • 104.24.14.43
  • 104.24.15.43
suspicious
anton.to
  • 104.27.135.31
  • 104.27.134.31
suspicious

Threats

No threats detected
No debug info