File name:

Uplay checker V2.0 By Scorpio (3).zip

Full analysis: https://app.any.run/tasks/cece415e-5a14-4fc1-9876-40b2c995fe19
Verdict: Malicious activity
Analysis date: January 08, 2020, 20:43:27
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

3CBF5484F6F2DDFCF53FBE074F24F516

SHA1:

57B986C5B9E7DBA2AED0D554A90AC8EB3F4F381B

SHA256:

04C7A956988F9B0F6D1DE457A1B283579DD02F2F2190F1EAE3B29E31C1D16E10

SSDEEP:

12288:dCw8uaivyPa8+kItxbYcZUDu2eR0IDpFvDAbB:dCwLaivyCSITBH0sTS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3504)
      • Uplay checker V2.0 by scorpio.exe (PID: 1912)
    • Application was dropped or rewritten from another process

      • Uplay checker V2.0 by scorpio.exe (PID: 1912)
    • Connects to CnC server

      • Uplay checker V2.0 by scorpio.exe (PID: 1912)
  • SUSPICIOUS

    • Reads Internet Cache Settings

      • Uplay checker V2.0 by scorpio.exe (PID: 1912)
    • Reads Environment values

      • Uplay checker V2.0 by scorpio.exe (PID: 1912)
    • Connects to unusual port

      • Uplay checker V2.0 by scorpio.exe (PID: 1912)
  • INFO

    • Manual execution by user

      • Uplay checker V2.0 by scorpio.exe (PID: 1912)
    • Reads settings of System Certificates

      • Uplay checker V2.0 by scorpio.exe (PID: 1912)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2019:12:31 20:39:25
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Uplay checker V2.0 By Scorpio/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs searchprotocolhost.exe no specs uplay checker v2.0 by scorpio.exe

Process information

PID
CMD
Path
Indicators
Parent process
1912"C:\Users\admin\Desktop\Uplay checker V2.0 by scorpio.exe" C:\Users\admin\Desktop\Uplay checker V2.0 by scorpio.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Uplay checker V2.0 by scorpio
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\uplay checker v2.0 by scorpio.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2548"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Uplay checker V2.0 By Scorpio (3).zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3504"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
2 150
Read events
2 036
Write events
110
Delete events
4

Modification events

(PID) Process:(2548) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2548) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2548) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2548) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Uplay checker V2.0 By Scorpio (3).zip
(PID) Process:(2548) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2548) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2548) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2548) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3504) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3504) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
0
Suspicious files
4
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
2548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2548.23711\Uplay checker V2.0 By Scorpio\Newtonsoft.Json.dll
MD5:
SHA256:
2548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2548.23711\Uplay checker V2.0 By Scorpio\Uplay checker V2.0 by scorpio.exe
MD5:
SHA256:
2548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2548.23711\Uplay checker V2.0 By Scorpio\xNet.dll
MD5:
SHA256:
2548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2548.23711\Uplay checker V2.0 By Scorpio\Аккаунты юплей ДОХЕРА.txt
MD5:
SHA256:
2548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2548.23711\Uplay checker V2.0 By Scorpio\LZT PROXY 4.txt
MD5:
SHA256:
1912Uplay checker V2.0 by scorpio.exeC:\Users\admin\AppData\Local\Temp\Cab8175.tmp
MD5:
SHA256:
1912Uplay checker V2.0 by scorpio.exeC:\Users\admin\AppData\Local\Temp\Tar8176.tmp
MD5:
SHA256:
1912Uplay checker V2.0 by scorpio.exeC:\Users\admin\AppData\Local\Temp\Cab8187.tmp
MD5:
SHA256:
1912Uplay checker V2.0 by scorpio.exeC:\Users\admin\AppData\Local\Temp\Tar8188.tmp
MD5:
SHA256:
1912Uplay checker V2.0 by scorpio.exeC:\Users\admin\AppData\Local\Temp\Cab8254.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
5 526
DNS requests
12
Threats
4 359

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1912
Uplay checker V2.0 by scorpio.exe
GET
200
205.185.216.10:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
57.4 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1912
Uplay checker V2.0 by scorpio.exe
181.211.97.134:59855
CORPORACION NACIONAL DE TELECOMUNICACIONES - CNT EP
EC
suspicious
1912
Uplay checker V2.0 by scorpio.exe
217.21.54.173:4145
Velcom AZS LLC
BY
suspicious
1912
Uplay checker V2.0 by scorpio.exe
36.91.181.155:4145
ID
suspicious
1912
Uplay checker V2.0 by scorpio.exe
105.29.78.162:4145
SEACOM-AS
MU
suspicious
1912
Uplay checker V2.0 by scorpio.exe
103.12.150.254:37983
HK
suspicious
1912
Uplay checker V2.0 by scorpio.exe
101.255.117.2:51122
PT Remala Abadi
ID
suspicious
1912
Uplay checker V2.0 by scorpio.exe
91.210.96.1:4145
Kavkaz Internet Service Ltd.
RU
suspicious
1912
Uplay checker V2.0 by scorpio.exe
103.69.118.77:4145
Earth Network Technology (HongKong) Co., Limited
CN
suspicious
1912
Uplay checker V2.0 by scorpio.exe
185.47.184.253:45463
MVM NET Zrt.
HU
suspicious
1912
Uplay checker V2.0 by scorpio.exe
92.62.72.252:4145
Saimanet Telecomunications
KG
suspicious

DNS requests

Domain
IP
Reputation
api-ubiservices.ubi.com
  • 54.145.254.16
  • 54.163.211.139
  • 3.219.59.31
unknown
wspuplay-ext.ubi.com
  • 216.98.58.60
unknown
www.download.windowsupdate.com
  • 205.185.216.10
  • 205.185.216.42
whitelisted

Threats

PID
Process
Class
Message
1912
Uplay checker V2.0 by scorpio.exe
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
1912
Uplay checker V2.0 by scorpio.exe
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
1912
Uplay checker V2.0 by scorpio.exe
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
1912
Uplay checker V2.0 by scorpio.exe
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
1912
Uplay checker V2.0 by scorpio.exe
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
1912
Uplay checker V2.0 by scorpio.exe
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
1912
Uplay checker V2.0 by scorpio.exe
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
1912
Uplay checker V2.0 by scorpio.exe
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
1912
Uplay checker V2.0 by scorpio.exe
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
1912
Uplay checker V2.0 by scorpio.exe
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
No debug info