| File name: | clink_and_unxutils.zip |
| Full analysis: | https://app.any.run/tasks/34bbe5a1-4510-46c0-a892-10aaf8f34d83 |
| Verdict: | Malicious activity |
| Analysis date: | December 25, 2020, 17:37:10 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract |
| MD5: | 048BE1D70AB3650031F64311C7FDA7D0 |
| SHA1: | E84EE3B908C9105711E22E48C94586A2FC73B04C |
| SHA256: | 1AECA7B90D0F9FAA4C4562791889CB27808903EA1D53CA873BCE144EAA0ADE0C |
| SSDEEP: | 98304:vOUb4b7pYGhHNoeZBVr4Unvu2C5jpkwBfoeDdC1LeE0lIGp:2V7Rq+4UKB/Bg+0LeEtGp |
| .xpi | | | Mozilla Firefox browser extension (66.6) |
|---|---|---|
| .zip | | | ZIP compressed archive (33.3) |
| ZipRequiredVersion: | 10 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2018:08:19 14:50:23 |
| ZipCRC: | 0x83fd88af |
| ZipCompressedSize: | 3365638 |
| ZipUncompressedSize: | 3365638 |
| ZipFileName: | UnxUtils.zip |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 276 | "C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\UnxUpdates.zip" C:\Users\admin\Desktop\ | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 1116 | "C:\Users\admin\Desktop\zsh.exe" | C:\Users\admin\Desktop\zsh.exe | zsh.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221225477 Modules
| |||||||||||||||
| 1892 | "C:\Program Files\clink\0.4.9\clink_x86.exe" autorun install --profile "~\clink" | C:\Program Files\clink\0.4.9\clink_x86.exe | — | clink_0.4.9_setup.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1968 | "C:\Users\admin\Desktop\cat.exe" | C:\Users\admin\Desktop\cat.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221225786 Modules
| |||||||||||||||
| 1984 | "C:\Windows\system32\cmd.exe" | C:\Windows\system32\cmd.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 3221225786 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2288 | "C:\Users\admin\Desktop\zsh.exe" | C:\Users\admin\Desktop\zsh.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3 Modules
| |||||||||||||||
| 2396 | "C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\clink_and_unxutils.zip" C:\Users\admin\Desktop\ | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2396 | "C:\Program Files\clink\0.4.9\clink_x86.exe" autorun --allusers uninstall | C:\Program Files\clink\0.4.9\clink_x86.exe | — | clink_0.4.9_setup.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2404 | "C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\UnxUtils.zip" C:\Users\admin\Desktop\ | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2488 | "C:\Users\admin\Desktop\zsh.exe" | C:\Users\admin\Desktop\zsh.exe | zsh.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221225477 Modules
| |||||||||||||||
| (PID) Process: | (3652) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Windows\eHome\ehshell.exe |
Value: Windows Media Center | |||
| (PID) Process: | (3652) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe |
Value: Adobe Acrobat Reader DC | |||
| (PID) Process: | (3652) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Program Files\Windows NT\Accessories\WORDPAD.EXE |
Value: WordPad | |||
| (PID) Process: | (3652) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Program Files\Windows Media Player\wmplayer.exe |
Value: Windows Media Player | |||
| (PID) Process: | (3652) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\167\52C64B7E |
| Operation: | write | Name: | @wmploc.dll,-102 |
Value: Windows Media Player | |||
| (PID) Process: | (3652) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\167\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3652) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Value: Microsoft Word | |||
| (PID) Process: | (3652) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Program Files\VideoLAN\VLC\vlc.exe |
Value: VLC media player | |||
| (PID) Process: | (3652) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Program Files\Windows Photo Viewer\PhotoViewer.dll |
Value: Windows Photo Viewer | |||
| (PID) Process: | (3652) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Program Files\Opera\Opera.exe |
Value: Opera Internet Browser | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2396 | WinRAR.exe | C:\Users\admin\Desktop\clink_0.4.9_setup.exe | executable | |
MD5:— | SHA256:— | |||
| 2396 | WinRAR.exe | C:\Users\admin\Desktop\UnxUpdates.zip | compressed | |
MD5:— | SHA256:— | |||
| 2396 | WinRAR.exe | C:\Users\admin\Desktop\UnxUtils.zip | compressed | |
MD5:— | SHA256:— | |||
| 3904 | clink_0.4.9_setup.exe | C:\Program Files\clink\0.4.9\clink.lua | text | |
MD5:— | SHA256:— | |||
| 3904 | clink_0.4.9_setup.exe | C:\Program Files\clink\0.4.9\clink_dll_x64.dll | executable | |
MD5:9BD6CCC6EDFA080798782BF2F01D33CC | SHA256:B7EDCEE9CB165A9ED32D9313FA93A8822892E33CAE9892F0BE4D7A88E3ACE7F3 | |||
| 3904 | clink_0.4.9_setup.exe | C:\Program Files\clink\0.4.9\clink_dll_x86.dll | executable | |
MD5:4E85C9DB2010DB0A8B4DD23E4759FEE2 | SHA256:1A723B3C12E935EB7F8B261B87AB0779A1DD04A831F481561AC598D312F2049F | |||
| 2568 | clink_x86.exe | C:\Users\admin\AppData\Local\clink\clink.log | text | |
MD5:— | SHA256:— | |||
| 3904 | clink_0.4.9_setup.exe | C:\Program Files\clink\0.4.9\clink.html | html | |
MD5:— | SHA256:— | |||
| 3904 | clink_0.4.9_setup.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\clink\0.4.9\Clink v0.4.9.lnk | lnk | |
MD5:— | SHA256:— | |||
| 3904 | clink_0.4.9_setup.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\clink\0.4.9\Clink v0.4.9 Documentation.lnk | lnk | |
MD5:— | SHA256:— | |||