analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

GABB.rar

Full analysis: https://app.any.run/tasks/494f1ab0-d33d-4c2d-8259-549e4ae49fec
Verdict: Malicious activity
Analysis date: August 08, 2020, 12:54:24
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

1A276B0117098EE94FADB1B1496D81DD

SHA1:

CC9A7B76A5FF53950ACBE6E1AA27D579267305E1

SHA256:

FD1848088DCAF302B08C5CD95C225A3CE981332EB357E110BD1C95E19B4E8AEB

SSDEEP:

24576:4Kakz7ynLA37lPxV4y5N0OcyV2ceBL+kYtqQFy/FVNek0r19V:HakPynLAlv4y5JpJFqwx1n

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • GABB Cleaned.exe (PID: 2752)
      • GABB.exe (PID: 1248)
    • Loads dropped or rewritten executable

      • explorer.exe (PID: 468)
      • GABB.exe (PID: 1248)
    • Changes the autorun value in the registry

      • GABB Cleaned.exe (PID: 2752)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • explorer.exe (PID: 468)
      • WinRAR.exe (PID: 2288)
      • GABB Cleaned.exe (PID: 2752)
    • Checks for external IP

      • GABB Cleaned.exe (PID: 2752)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start winrar.exe explorer.exe gabb cleaned.exe gabb.exe no specs notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2288"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\GABB.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
468C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
2752"C:\Users\admin\Desktop\New folder\GABB Cleaned.exe" C:\Users\admin\Desktop\New folder\GABB Cleaned.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Version:
1.0.0.0
1248"C:\Users\admin\AppData\Local\Temp\GABB.exe" C:\Users\admin\AppData\Local\Temp\GABB.exeGABB Cleaned.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
3188"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\GABB.iniC:\Windows\system32\NOTEPAD.EXEGABB Cleaned.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
4 661
Read events
4 494
Write events
0
Delete events
0

Modification events

No data
Executable files
7
Suspicious files
0
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
2288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2288.11640\GABB Cleaned.exe
MD5:
SHA256:
468explorer.exeC:\Users\admin\Desktop\New folder\GABB Cleaned.exeexecutable
MD5:4FA52E3B0FC5C828FA699BD385943192
SHA256:C0B0A37BE2BF94355A82C680E929B55084EAB66040E2A7DAB6C6349C5D569245
2288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2288.11640\GABB.initext
MD5:C4A166CFFF95A111FEA5474A95928F2C
SHA256:3B45F4BC47C7DEF7BDBE886DFECBBB5DBC8335998B4D925978A114DEFE8C8DC9
2752GABB Cleaned.exeC:\Users\admin\AppData\Local\Temp\GABB.initext
MD5:78E850A5916CB4D96A41FE35D8007B7B
SHA256:81E4BBF799A67BCC0EC71BE5B4C34405D2982B25506685E6C40EB58B6709DF51
468explorer.exeC:\Users\admin\Desktop\New folder\GABB.initext
MD5:C4A166CFFF95A111FEA5474A95928F2C
SHA256:3B45F4BC47C7DEF7BDBE886DFECBBB5DBC8335998B4D925978A114DEFE8C8DC9
468explorer.exeC:\Users\admin\Desktop\GABB Cleaned.exeexecutable
MD5:4FA52E3B0FC5C828FA699BD385943192
SHA256:C0B0A37BE2BF94355A82C680E929B55084EAB66040E2A7DAB6C6349C5D569245
468explorer.exeC:\Users\admin\Desktop\GABB.initext
MD5:C4A166CFFF95A111FEA5474A95928F2C
SHA256:3B45F4BC47C7DEF7BDBE886DFECBBB5DBC8335998B4D925978A114DEFE8C8DC9
468explorer.exeC:\Users\admin\Desktop\GDLL.dllexecutable
MD5:8A12CB004CDBAAA80114F3C183848EFD
SHA256:92C1C18666563DF90CCA6C49CDA917B569061AE23ECD1556148E231CD6420517
2752GABB Cleaned.exeC:\Users\admin\AppData\Local\Temp\GABB.exeexecutable
MD5:C38456546C2319303F3E40B0AB1FE9B6
SHA256:621200CE896C664951FE89A0C04D282F6A633AE064B2D9D7E2C06F01FE743E00
1248GABB.exeC:\Users\admin\Desktop\New folder\GABB.initext
MD5:B1B8FE3658ACFA008FC6B19C2CA7BCCB
SHA256:623E4356C58DFA235FB83EEBD1187D6C110000A66DE7CA9B30CD323C16D9BF11
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
3
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2752
GABB Cleaned.exe
GET
200
116.202.55.106:80
http://icanhazip.com/
IN
text
14 b
shared
2752
GABB Cleaned.exe
GET
200
116.202.55.106:80
http://icanhazip.com/
IN
text
14 b
shared
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2752
GABB Cleaned.exe
116.202.55.106:80
icanhazip.com
334,Udyog Vihar
IN
malicious
2752
GABB Cleaned.exe
104.27.143.46:443
nusumu.wtf
Cloudflare Inc
US
malicious

DNS requests

Domain
IP
Reputation
icanhazip.com
  • 116.202.55.106
  • 116.202.244.153
shared
nusumu.wtf
  • 104.27.143.46
  • 172.67.214.70
  • 104.27.142.46
unknown

Threats

PID
Process
Class
Message
2752
GABB Cleaned.exe
Attempted Information Leak
ET POLICY IP Check Domain (icanhazip. com in HTTP Host)
2752
GABB Cleaned.exe
Attempted Information Leak
ET POLICY IP Check Domain (icanhazip. com in HTTP Host)
No debug info