File name:

clink_and_unxutils.zip

Full analysis: https://app.any.run/tasks/34bbe5a1-4510-46c0-a892-10aaf8f34d83
Verdict: Malicious activity
Analysis date: December 25, 2020, 17:37:10
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

048BE1D70AB3650031F64311C7FDA7D0

SHA1:

E84EE3B908C9105711E22E48C94586A2FC73B04C

SHA256:

1AECA7B90D0F9FAA4C4562791889CB27808903EA1D53CA873BCE144EAA0ADE0C

SSDEEP:

98304:vOUb4b7pYGhHNoeZBVr4Unvu2C5jpkwBfoeDdC1LeE0lIGp:2V7Rq+4UKB/Bg+0LeEtGp

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • WinRAR.exe (PID: 2396)
      • WinRAR.exe (PID: 276)
      • WinRAR.exe (PID: 2404)
    • Application was dropped or rewritten from another process

      • clink_0.4.9_setup.exe (PID: 2640)
      • clink_0.4.9_setup.exe (PID: 3904)
      • clink_x86.exe (PID: 2396)
      • clink_x86.exe (PID: 2568)
      • clink_x86.exe (PID: 1892)
      • cat.exe (PID: 1968)
      • zsh.exe (PID: 2288)
      • zsh.exe (PID: 3624)
      • zsh.exe (PID: 1116)
      • zsh.exe (PID: 3412)
      • zsh.exe (PID: 2488)
    • Loads dropped or rewritten executable

      • clink_x86.exe (PID: 2568)
      • cmd.exe (PID: 1984)
  • SUSPICIOUS

    • Checks supported languages

      • WinRAR.exe (PID: 2396)
      • clink_0.4.9_setup.exe (PID: 3904)
      • clink_x86.exe (PID: 2396)
      • clink_x86.exe (PID: 1892)
      • clink_x86.exe (PID: 2568)
      • cmd.exe (PID: 1984)
      • tree.com (PID: 3356)
      • cat.exe (PID: 1968)
      • WinRAR.exe (PID: 2404)
      • WinRAR.exe (PID: 276)
      • zsh.exe (PID: 3624)
      • zsh.exe (PID: 3412)
      • zsh.exe (PID: 1116)
      • zsh.exe (PID: 2488)
      • zsh.exe (PID: 2288)
    • Reads the computer name

      • WinRAR.exe (PID: 2396)
      • clink_0.4.9_setup.exe (PID: 3904)
      • WinRAR.exe (PID: 276)
      • WinRAR.exe (PID: 2404)
      • zsh.exe (PID: 2288)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2396)
      • clink_0.4.9_setup.exe (PID: 3904)
      • WinRAR.exe (PID: 276)
      • WinRAR.exe (PID: 2404)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 2396)
      • clink_0.4.9_setup.exe (PID: 3904)
      • WinRAR.exe (PID: 276)
      • WinRAR.exe (PID: 2404)
    • Creates a directory in Program Files

      • clink_0.4.9_setup.exe (PID: 3904)
    • Creates files in the program directory

      • clink_0.4.9_setup.exe (PID: 3904)
    • Creates a software uninstall entry

      • clink_0.4.9_setup.exe (PID: 3904)
    • Starts application with an unusual extension

      • cmd.exe (PID: 1984)
    • Drops a file that was compiled in debug mode

      • clink_0.4.9_setup.exe (PID: 3904)
      • WinRAR.exe (PID: 2404)
    • Application launched itself

      • zsh.exe (PID: 2288)
  • INFO

    • Checks supported languages

      • rundll32.exe (PID: 3652)
      • explorer.exe (PID: 3580)
    • Reads the computer name

      • rundll32.exe (PID: 3652)
      • explorer.exe (PID: 3580)
    • Manual execution by user

      • explorer.exe (PID: 3580)
      • WinRAR.exe (PID: 2396)
      • clink_0.4.9_setup.exe (PID: 2640)
      • clink_0.4.9_setup.exe (PID: 3904)
      • cmd.exe (PID: 1984)
      • WinRAR.exe (PID: 276)
      • cat.exe (PID: 1968)
      • WinRAR.exe (PID: 2404)
      • zsh.exe (PID: 2288)
    • Dropped object may contain Bitcoin addresses

      • WinRAR.exe (PID: 2404)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xpi | Mozilla Firefox browser extension (66.6)
.zip | ZIP compressed archive (33.3)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2018:08:19 14:50:23
ZipCRC: 0x83fd88af
ZipCompressedSize: 3365638
ZipUncompressedSize: 3365638
ZipFileName: UnxUtils.zip
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
75
Monitored processes
18
Malicious processes
7
Suspicious processes
3

Behavior graph

Click at the process to see the details
start drop and start drop and start rundll32.exe no specs explorer.exe no specs winrar.exe clink_0.4.9_setup.exe no specs clink_0.4.9_setup.exe clink_x86.exe no specs clink_x86.exe no specs cmd.exe no specs clink_x86.exe no specs tree.com no specs winrar.exe cat.exe no specs winrar.exe zsh.exe no specs zsh.exe zsh.exe zsh.exe zsh.exe

Process information

PID
CMD
Path
Indicators
Parent process
276"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\UnxUpdates.zip" C:\Users\admin\Desktop\C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\shell32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
1116"C:\Users\admin\Desktop\zsh.exe"C:\Users\admin\Desktop\zsh.exe
zsh.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225477
Modules
Images
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
1892"C:\Program Files\clink\0.4.9\clink_x86.exe" autorun install --profile "~\clink"C:\Program Files\clink\0.4.9\clink_x86.execlink_0.4.9_setup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\program files\clink\0.4.9\clink_x86.exe
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1968"C:\Users\admin\Desktop\cat.exe" C:\Users\admin\Desktop\cat.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225786
Modules
Images
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\cat.exe
c:\windows\system32\msvcrt.dll
1984"C:\Windows\system32\cmd.exe" C:\Windows\system32\cmd.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
3221225786
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\cmd.exe
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\windows\system32\usp10.dll
2288"C:\Users\admin\Desktop\zsh.exe" C:\Users\admin\Desktop\zsh.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
3
Modules
Images
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\users\admin\desktop\zsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\user32.dll
2396"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\clink_and_unxutils.zip" C:\Users\admin\Desktop\C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\shell32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
2396"C:\Program Files\clink\0.4.9\clink_x86.exe" autorun --allusers uninstallC:\Program Files\clink\0.4.9\clink_x86.execlink_0.4.9_setup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\program files\clink\0.4.9\clink_x86.exe
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\shlwapi.dll
2404"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\UnxUtils.zip" C:\Users\admin\Desktop\C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24542_none_5c0717c7a00ddc6d\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\devobj.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
2488"C:\Users\admin\Desktop\zsh.exe"C:\Users\admin\Desktop\zsh.exe
zsh.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225477
Modules
Images
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\zsh.exe
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
Total events
1 183
Read events
1 131
Write events
52
Delete events
0

Modification events

(PID) Process:(3652) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Windows\eHome\ehshell.exe
Value:
Windows Media Center
(PID) Process:(3652) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
Value:
Adobe Acrobat Reader DC
(PID) Process:(3652) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
Value:
WordPad
(PID) Process:(3652) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\Windows Media Player\wmplayer.exe
Value:
Windows Media Player
(PID) Process:(3652) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\167\52C64B7E
Operation:writeName:@wmploc.dll,-102
Value:
Windows Media Player
(PID) Process:(3652) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\167\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3652) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Value:
Microsoft Word
(PID) Process:(3652) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\VideoLAN\VLC\vlc.exe
Value:
VLC media player
(PID) Process:(3652) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\Windows Photo Viewer\PhotoViewer.dll
Value:
Windows Photo Viewer
(PID) Process:(3652) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\Opera\Opera.exe
Value:
Opera Internet Browser
Executable files
159
Suspicious files
3
Text files
15
Unknown types
8

Dropped files

PID
Process
Filename
Type
2396WinRAR.exeC:\Users\admin\Desktop\clink_0.4.9_setup.exeexecutable
MD5:
SHA256:
2396WinRAR.exeC:\Users\admin\Desktop\UnxUpdates.zipcompressed
MD5:
SHA256:
2396WinRAR.exeC:\Users\admin\Desktop\UnxUtils.zipcompressed
MD5:
SHA256:
3904clink_0.4.9_setup.exeC:\Program Files\clink\0.4.9\clink.luatext
MD5:
SHA256:
3904clink_0.4.9_setup.exeC:\Program Files\clink\0.4.9\clink_dll_x64.dllexecutable
MD5:9BD6CCC6EDFA080798782BF2F01D33CC
SHA256:B7EDCEE9CB165A9ED32D9313FA93A8822892E33CAE9892F0BE4D7A88E3ACE7F3
3904clink_0.4.9_setup.exeC:\Program Files\clink\0.4.9\clink_dll_x86.dllexecutable
MD5:4E85C9DB2010DB0A8B4DD23E4759FEE2
SHA256:1A723B3C12E935EB7F8B261B87AB0779A1DD04A831F481561AC598D312F2049F
2568clink_x86.exeC:\Users\admin\AppData\Local\clink\clink.logtext
MD5:
SHA256:
3904clink_0.4.9_setup.exeC:\Program Files\clink\0.4.9\clink.htmlhtml
MD5:
SHA256:
3904clink_0.4.9_setup.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\clink\0.4.9\Clink v0.4.9.lnklnk
MD5:
SHA256:
3904clink_0.4.9_setup.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\clink\0.4.9\Clink v0.4.9 Documentation.lnklnk
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info