| File name: | Gorker Private TSP Edition.rar |
| Full analysis: | https://app.any.run/tasks/8658b757-2e72-436a-b4f3-c2ddbff5e1d3 |
| Verdict: | Malicious activity |
| Analysis date: | July 28, 2021, 16:57:31 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32 |
| MD5: | 98D191A9047F8C48A042B9F3C7FB1C06 |
| SHA1: | 75A78C50B3BD664F4D30EC2E4965C70EF98AB406 |
| SHA256: | F73471A328706816F8B427496F419E54D7788CF6EC96C52372DFFBA72C54EE4D |
| SSDEEP: | 6144:ys65uyBlK+DNKV2qAJummjo5aGzmJ/1xdge0mhObKmARmgKabdp1Ygm8Q0jTleWf:M57BbblwGMdo3GI41YgLvMWf |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| ArchivedFileName: | Gorker Private TSP Edition\custom_domainextensions.txt |
|---|---|
| PackingMethod: | Stored |
| ModifyDate: | 2018:03:22 18:45:19 |
| OperatingSystem: | Win32 |
| UncompressedSize: | 26 |
| CompressedSize: | 102 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1768 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Gorker Private TSP Edition.rar" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2748 | "C:\Users\admin\Desktop\Gorker Private TSP Edition\Gorker Private.exe" | C:\Users\admin\Desktop\Gorker Private TSP Edition\Gorker Private.exe | Explorer.EXE | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Gorker Private TSP Edition Exit code: 0 Version: 5.0 Modules
| |||||||||||||||
| 3428 | "C:\Users\admin\Desktop\Gorker Private TSP Edition\Gorker Private.exe" | C:\Users\admin\Desktop\Gorker Private TSP Edition\Gorker Private.exe | Explorer.EXE | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Gorker Private TSP Edition Exit code: 0 Version: 5.0 Modules
| |||||||||||||||
| 3512 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\system32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211) Modules
| |||||||||||||||
| 4088 | "C:\Users\admin\Desktop\Gorker Private TSP Edition\Gorker Private.exe" | C:\Users\admin\Desktop\Gorker Private TSP Edition\Gorker Private.exe | Explorer.EXE | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Gorker Private TSP Edition Exit code: 0 Version: 5.0 Modules
| |||||||||||||||
| (PID) Process: | (1768) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1768) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1768) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1768) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (1768) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Gorker Private TSP Edition.rar | |||
| (PID) Process: | (1768) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1768) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1768) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1768) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3512) SearchProtocolHost.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\16B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1768 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1768.13411\Gorker Private TSP Edition\Gorker Private.exe | executable | |
MD5:— | SHA256:— | |||
| 3428 | Gorker Private.exe | C:\Users\admin\Desktop\Gorker Private TSP Edition\Generated1.txt | text | |
MD5:— | SHA256:— | |||
| 1768 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1768.13411\Gorker Private TSP Edition\custom_domainextensions.txt | text | |
MD5:561B8CC2A5E145D78E61EF62B4D15D30 | SHA256:0F37CE78BE139CB3161C45F93FD2E7D502124EF349D9E9DC95386E46350B7A89 | |||
| 1768 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1768.13411\Gorker Private TSP Edition\default_domainextensions.txt | text | |
MD5:67815BB37D3B3D1BF9CD8D247DF71921 | SHA256:AB11A70EEF7BA2A8F146864EC8A4E675C0834A71E02087B86815EEF7F3B1F4AD | |||
| 1768 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1768.13411\Gorker Private TSP Edition\default_pagetypes.txt | text | |
MD5:528DE96ECB5A0CC60839B0F2725D54EB | SHA256:29B4D80F7000C874C3DE514AA631EAB06961697EDE63CFDE76DC1F9687E4A60D | |||
| 1768 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1768.13411\Gorker Private TSP Edition\MetroFramework.Design.dll | executable | |
MD5:AB4C3529694FC8D2427434825F71B2B8 | SHA256:0A4A96082E25767E4697033649B16C76A652E120757A2CECAB8092AD0D716B65 | |||
| 1768 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1768.13411\Gorker Private TSP Edition\MetroFramework.Fonts.dll | executable | |
MD5:65EF4B23060128743CEF937A43B82AA3 | SHA256:C843869AACA5135C2D47296985F35C71CA8AF4431288D04D481C4E46CC93EE26 | |||
| 1768 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1768.13411\Gorker Private TSP Edition\default_numbers.txt | text | |
MD5:43E851F5155BCCDD354E552B37545743 | SHA256:4ADE471B36D69CF34126075BC336C17A3B260DD040AFD3B75D6D65B6D95FA8C7 | |||
| 1768 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1768.13411\Gorker Private TSP Edition\default_pageformats.txt | text | |
MD5:BBAB0AAF7B5D1F26CECCFFCD481A48D0 | SHA256:56792D6BB095E346D2E5A83F3703ECF9C51849E4CD58527027ABCAA1A6C44598 | |||
| 1768 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1768.13411\Gorker Private TSP Edition\MetroFramework.dll | executable | |
MD5:34EA7F7D66563F724318E322FF08F4DB | SHA256:C2C12D31B4844E29DE31594FC9632A372A553631DE0A0A04C8AF91668E37CF49 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2748 | Gorker Private.exe | 162.125.66.15:443 | dl.dropbox.com | Dropbox, Inc. | DE | malicious |
4088 | Gorker Private.exe | 162.125.66.15:443 | dl.dropbox.com | Dropbox, Inc. | DE | malicious |
3428 | Gorker Private.exe | 162.125.66.15:443 | dl.dropbox.com | Dropbox, Inc. | DE | malicious |
Domain | IP | Reputation |
|---|---|---|
dl.dropbox.com |
| shared |
dl.dropboxusercontent.com |
| shared |