File name:

Gorker Private TSP Edition.rar

Full analysis: https://app.any.run/tasks/8658b757-2e72-436a-b4f3-c2ddbff5e1d3
Verdict: Malicious activity
Analysis date: July 28, 2021, 16:57:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

98D191A9047F8C48A042B9F3C7FB1C06

SHA1:

75A78C50B3BD664F4D30EC2E4965C70EF98AB406

SHA256:

F73471A328706816F8B427496F419E54D7788CF6EC96C52372DFFBA72C54EE4D

SSDEEP:

6144:ys65uyBlK+DNKV2qAJummjo5aGzmJ/1xdge0mhObKmARmgKabdp1Ygm8Q0jTleWf:M57BbblwGMdo3GI41YgLvMWf

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3512)
      • Gorker Private.exe (PID: 2748)
      • Gorker Private.exe (PID: 4088)
      • Gorker Private.exe (PID: 3428)
    • Application was dropped or rewritten from another process

      • Gorker Private.exe (PID: 2748)
      • Gorker Private.exe (PID: 4088)
      • Gorker Private.exe (PID: 3428)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1768)
    • Reads the computer name

      • WinRAR.exe (PID: 1768)
      • Gorker Private.exe (PID: 2748)
      • Gorker Private.exe (PID: 4088)
      • Gorker Private.exe (PID: 3428)
    • Checks supported languages

      • WinRAR.exe (PID: 1768)
      • Gorker Private.exe (PID: 2748)
      • Gorker Private.exe (PID: 4088)
      • Gorker Private.exe (PID: 3428)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 1768)
    • Reads Environment values

      • Gorker Private.exe (PID: 2748)
      • Gorker Private.exe (PID: 4088)
      • Gorker Private.exe (PID: 3428)
  • INFO

    • Manual execution by user

      • Gorker Private.exe (PID: 2748)
      • Gorker Private.exe (PID: 4088)
      • Gorker Private.exe (PID: 3428)
    • Reads settings of System Certificates

      • Gorker Private.exe (PID: 2748)
      • Gorker Private.exe (PID: 3428)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

ArchivedFileName: Gorker Private TSP Edition\custom_domainextensions.txt
PackingMethod: Stored
ModifyDate: 2018:03:22 18:45:19
OperatingSystem: Win32
UncompressedSize: 26
CompressedSize: 102
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
5
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs gorker private.exe gorker private.exe gorker private.exe

Process information

PID
CMD
Path
Indicators
Parent process
1768"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Gorker Private TSP Edition.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2748"C:\Users\admin\Desktop\Gorker Private TSP Edition\Gorker Private.exe" C:\Users\admin\Desktop\Gorker Private TSP Edition\Gorker Private.exe
Explorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Gorker Private TSP Edition
Exit code:
0
Version:
5.0
Modules
Images
c:\users\admin\desktop\gorker private tsp edition\gorker private.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3428"C:\Users\admin\Desktop\Gorker Private TSP Edition\Gorker Private.exe" C:\Users\admin\Desktop\Gorker Private TSP Edition\Gorker Private.exe
Explorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Gorker Private TSP Edition
Exit code:
0
Version:
5.0
Modules
Images
c:\users\admin\desktop\gorker private tsp edition\gorker private.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\rpcrt4.dll
3512"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
4088"C:\Users\admin\Desktop\Gorker Private TSP Edition\Gorker Private.exe" C:\Users\admin\Desktop\Gorker Private TSP Edition\Gorker Private.exe
Explorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Gorker Private TSP Edition
Exit code:
0
Version:
5.0
Modules
Images
c:\users\admin\desktop\gorker private tsp edition\gorker private.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
8 369
Read events
8 322
Write events
47
Delete events
0

Modification events

(PID) Process:(1768) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1768) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1768) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1768) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1768) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Gorker Private TSP Edition.rar
(PID) Process:(1768) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1768) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1768) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1768) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3512) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\16B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
4
Suspicious files
0
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
1768WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1768.13411\Gorker Private TSP Edition\Gorker Private.exeexecutable
MD5:
SHA256:
3428Gorker Private.exeC:\Users\admin\Desktop\Gorker Private TSP Edition\Generated1.txttext
MD5:
SHA256:
1768WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1768.13411\Gorker Private TSP Edition\custom_domainextensions.txttext
MD5:561B8CC2A5E145D78E61EF62B4D15D30
SHA256:0F37CE78BE139CB3161C45F93FD2E7D502124EF349D9E9DC95386E46350B7A89
1768WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1768.13411\Gorker Private TSP Edition\default_domainextensions.txttext
MD5:67815BB37D3B3D1BF9CD8D247DF71921
SHA256:AB11A70EEF7BA2A8F146864EC8A4E675C0834A71E02087B86815EEF7F3B1F4AD
1768WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1768.13411\Gorker Private TSP Edition\default_pagetypes.txttext
MD5:528DE96ECB5A0CC60839B0F2725D54EB
SHA256:29B4D80F7000C874C3DE514AA631EAB06961697EDE63CFDE76DC1F9687E4A60D
1768WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1768.13411\Gorker Private TSP Edition\MetroFramework.Design.dllexecutable
MD5:AB4C3529694FC8D2427434825F71B2B8
SHA256:0A4A96082E25767E4697033649B16C76A652E120757A2CECAB8092AD0D716B65
1768WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1768.13411\Gorker Private TSP Edition\MetroFramework.Fonts.dllexecutable
MD5:65EF4B23060128743CEF937A43B82AA3
SHA256:C843869AACA5135C2D47296985F35C71CA8AF4431288D04D481C4E46CC93EE26
1768WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1768.13411\Gorker Private TSP Edition\default_numbers.txttext
MD5:43E851F5155BCCDD354E552B37545743
SHA256:4ADE471B36D69CF34126075BC336C17A3B260DD040AFD3B75D6D65B6D95FA8C7
1768WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1768.13411\Gorker Private TSP Edition\default_pageformats.txttext
MD5:BBAB0AAF7B5D1F26CECCFFCD481A48D0
SHA256:56792D6BB095E346D2E5A83F3703ECF9C51849E4CD58527027ABCAA1A6C44598
1768WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1768.13411\Gorker Private TSP Edition\MetroFramework.dllexecutable
MD5:34EA7F7D66563F724318E322FF08F4DB
SHA256:C2C12D31B4844E29DE31594FC9632A372A553631DE0A0A04C8AF91668E37CF49
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2748
Gorker Private.exe
162.125.66.15:443
dl.dropbox.com
Dropbox, Inc.
DE
malicious
4088
Gorker Private.exe
162.125.66.15:443
dl.dropbox.com
Dropbox, Inc.
DE
malicious
3428
Gorker Private.exe
162.125.66.15:443
dl.dropbox.com
Dropbox, Inc.
DE
malicious

DNS requests

Domain
IP
Reputation
dl.dropbox.com
  • 162.125.66.15
shared
dl.dropboxusercontent.com
  • 162.125.66.15
shared

Threats

No threats detected
No debug info