File name:

Proxo_V1.4.rar

Full analysis: https://app.any.run/tasks/4dd06e40-910b-4aee-b634-a3ef47baaeae
Verdict: Malicious activity
Analysis date: January 25, 2019, 13:36:12
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

4C5CB122D5F29FC81AB4CBEE8EEEBB69

SHA1:

559A2640F4BC0A9F7E2B8C5D479857986B5449D9

SHA256:

F4AE7E42FA8389709CFE8701C9E04D35E388D0D8A8C96E2B6153C3775423E5C2

SSDEEP:

24576:swPbJ1mg6t5fIH76f1sBwieH66xDC/m9OEdlEw8960q4cugsN9:swPbJiIb6dsB+VDBpsI9ud9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Proxo.exe (PID: 3520)
      • Proxo Injector.exe (PID: 2072)
      • Lag Switch.exe (PID: 2236)
      • Multiple_ROBLOX.exe (PID: 3300)
      • Proxo.exe (PID: 1644)
    • Loads dropped or rewritten executable

      • Proxo.exe (PID: 3520)
      • Proxo Injector.exe (PID: 2072)
      • Proxo.exe (PID: 1644)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3000)
    • Reads Environment values

      • Lag Switch.exe (PID: 2236)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • WinRAR.exe (PID: 3000)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
6
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
drop and start drop and start drop and start drop and start drop and start start winrar.exe proxo.exe no specs proxo injector.exe no specs lag switch.exe multiple_roblox.exe no specs proxo.exe

Process information

PID
CMD
Path
Indicators
Parent process
1644"C:\Users\admin\AppData\Local\Temp\Rar$EXa3000.41637\Proxo V1.4\Proxo.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3000.41637\Proxo V1.4\Proxo.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Proxo
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3000.41637\proxo v1.4\proxo.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2072"C:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40660\Proxo V1.4\Proxo Injector.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40660\Proxo V1.4\Proxo Injector.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
ProxoInstaller
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3000.40660\proxo v1.4\proxo injector.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2236"C:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40854\Proxo V1.4\Lag Switch.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40854\Proxo V1.4\Lag Switch.exe
WinRAR.exe
User:
admin
Company:
JonathonPowell
Integrity Level:
MEDIUM
Description:
Lag Switch
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3000.40854\proxo v1.4\lag switch.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3000"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Proxo_V1.4.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3300"C:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40983\Proxo V1.4\Multiple_ROBLOX.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40983\Proxo V1.4\Multiple_ROBLOX.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Multiple ROBLOX
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3000.40983\proxo v1.4\multiple_roblox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3520"C:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40102\Proxo V1.4\Proxo.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40102\Proxo V1.4\Proxo.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Proxo
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3000.40102\proxo v1.4\proxo.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
526
Read events
469
Write events
57
Delete events
0

Modification events

(PID) Process:(3000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3000) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Proxo_V1.4.rar
(PID) Process:(3000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
40
Suspicious files
0
Text files
45
Unknown types
0

Dropped files

PID
Process
Filename
Type
3000WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40102\Proxo V1.4\Proxo Injector.exeexecutable
MD5:
SHA256:
3000WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40102\Proxo V1.4\Proxo.exeexecutable
MD5:
SHA256:
3000WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40102\Proxo V1.4\Scripts\Admin_for_auto_rap_suxxxx.txttext
MD5:
SHA256:
3000WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40102\Proxo V1.4\Scripts\HttpGet RoseHub.txttext
MD5:
SHA256:
3000WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40102\Proxo V1.4\WeAreDevs_API.dllexecutable
MD5:
SHA256:
3000WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40102\Proxo V1.4\Bunifu_UI_v1.5.3.dllexecutable
MD5:E0EF2817EE5A7C8CD1EB837195768BD2
SHA256:76E1D3EC95FDEF74ABAF90392DD6F4AA5E344922ABF11E572707287D467F2930
3000WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40102\Proxo V1.4\Scripts\[FE] Fling (R15).txttext
MD5:F43F24448C0C79AB66E45BAE4348CD74
SHA256:E5284714000A61048AC7828CD84F953EA68E01FC65279C5A88936374BD4FF0E7
3000WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40102\Proxo V1.4\Scripts\[FE] Funny.txttext
MD5:F6671C55D2C44039F125A6FA576B3E96
SHA256:6D7FCB115D5F60B34B10446DE8F53CDAC4910F49B59936D21FBC075CDC776BED
3000WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40102\Proxo V1.4\Scripts\[FE] Fling (R6).txttext
MD5:E7BA845AE5BD734981281B04B61C32CE
SHA256:223B0D55F74CDB0CA3F81BF886690B2F703C5614F716C07F5D841488D5C6089B
3000WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3000.40102\Proxo V1.4\Scripts\[FE] Dab.txttext
MD5:07B9E2FF159D00759B0AA0532762E623
SHA256:835D33BB4C894DD8BBD23F37533B24B6F0D66B5FA4D732F6B917265493F7F787
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
3
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2236
Lag Switch.exe
GET
301
104.24.14.43:80
http://www.wearedevs.net/Assets/softwaredetails.txt
US
suspicious
2236
Lag Switch.exe
GET
301
104.24.14.43:80
http://www.wearedevs.net/Assets/softwaredetails.txt
US
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2236
Lag Switch.exe
104.24.14.43:443
www.wearedevs.net
Cloudflare Inc
US
shared
1644
Proxo.exe
104.27.135.31:443
anton.to
Cloudflare Inc
US
shared
2236
Lag Switch.exe
104.24.14.43:80
www.wearedevs.net
Cloudflare Inc
US
shared

DNS requests

Domain
IP
Reputation
www.wearedevs.net
  • 104.24.14.43
  • 104.24.15.43
suspicious
anton.to
  • 104.27.135.31
  • 104.27.134.31
suspicious

Threats

No threats detected
No debug info