File name:

UltraISO_9.7.6.3810_Portable.rar

Full analysis: https://app.any.run/tasks/4ce9ae99-8cdd-4118-bdfa-24eb5243bb3d
Verdict: Malicious activity
Analysis date: October 02, 2024, 20:40:26
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

16A8C08F8E5226E6A804C9F0B5065B04

SHA1:

181454BED596A41C3327C4C8D34757DDA72360F1

SHA256:

1BB89E7E6097D051787054530177C3E607BCF95F88DA8E2E7F4F4DEF3982DFC8

SSDEEP:

98304:YgLXeRoxhXsn2NjEtPujtVsB7l+0PFmkohWr3PN36/P2PEzOMZ+ouDxsOWG58IRG:SWta27

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • UltraISOPortable.exe (PID: 6324)
      • UltraISOPortable.exe (PID: 6644)
    • Executable content was dropped or overwritten

      • UltraISOPortable.exe (PID: 6644)
      • UltraISOPortable.exe (PID: 6324)
    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 3272)
    • Application launched itself

      • UltraISOPortable.exe (PID: 6324)
    • Uses REG/REGEDIT.EXE to modify registry

      • UltraISOPortable.exe (PID: 6644)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3272)
    • Manual execution by a user

      • UltraISOPortable.exe (PID: 6324)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
134
Monitored processes
7
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe ultraisoportable.exe ultraisoportable.exe regedit.exe no specs isocmd.exe no specs conhost.exe no specs ultraiso.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3272"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\UltraISO_9.7.6.3810_Portable.rarC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3648\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeIsoCmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5700"C:\Users\admin\Desktop\UltraISO 9.7.6.3810 Portable\UltraISOPortable\App\UltraISO\UltraISO.exe" /UAC:110330 /NCRCC:\Users\admin\Desktop\UltraISO 9.7.6.3810 Portable\UltraISOPortable\App\UltraISO\UltraISO.exeUltraISOPortable.exe
User:
admin
Company:
EZB Systems, Inc.
Integrity Level:
HIGH
Description:
UltraISO Premium
Version:
9.7.6.3810
Modules
Images
c:\users\admin\desktop\ultraiso 9.7.6.3810 portable\ultraisoportable\app\ultraiso\ultraiso.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\setupapi.dll
6324"C:\Users\admin\Desktop\UltraISO 9.7.6.3810 Portable\UltraISOPortable\UltraISOPortable.exe" C:\Users\admin\Desktop\UltraISO 9.7.6.3810 Portable\UltraISOPortable\UltraISOPortable.exe
explorer.exe
User:
admin
Company:
9649
Integrity Level:
MEDIUM
Description:
UltraISO Premium
Version:
2.2.1.0
Modules
Images
c:\users\admin\desktop\ultraiso 9.7.6.3810 portable\ultraisoportable\ultraisoportable.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6576"C:\WINDOWS\regedit.exe" /s "C:\Users\admin\Desktop\UltraISO 9.7.6.3810 Portable\UltraISOPortable\Data\settings\UltraISO.reg"C:\Windows\SysWOW64\regedit.exeUltraISOPortable.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Editor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regedit.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6644"C:\Users\admin\Desktop\UltraISO 9.7.6.3810 Portable\UltraISOPortable\UltraISOPortable.exe" /UAC:110330 /NCRC C:\Users\admin\Desktop\UltraISO 9.7.6.3810 Portable\UltraISOPortable\UltraISOPortable.exe
UltraISOPortable.exe
User:
admin
Company:
9649
Integrity Level:
HIGH
Description:
UltraISO Premium
Version:
2.2.1.0
Modules
Images
c:\users\admin\desktop\ultraiso 9.7.6.3810 portable\ultraisoportable\ultraisoportable.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7028"C:\Users\admin\Desktop\UltraISO 9.7.6.3810 Portable\UltraISOPortable\App\UltraISO\drivers\IsoCmd.exe" -iC:\Users\admin\Desktop\UltraISO 9.7.6.3810 Portable\UltraISOPortable\App\UltraISO\drivers\IsoCmd.exeUltraISOPortable.exe
User:
admin
Company:
EZB Systems, Inc.
Integrity Level:
HIGH
Description:
ISO Command
Exit code:
0
Version:
3.20 built by: WinDDK
Modules
Images
c:\users\admin\desktop\ultraiso 9.7.6.3810 portable\ultraisoportable\app\ultraiso\drivers\isocmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
Total events
3 654
Read events
2 446
Write events
498
Delete events
710

Modification events

(PID) Process:(3272) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(3272) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\UltraISO_9.7.6.3810_Portable.rar
(PID) Process:(3272) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3272) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3272) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3272) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3272) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(3272) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
(PID) Process:(3272) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3272) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:psize
Value:
80
Executable files
58
Suspicious files
2
Text files
11
Unknown types
0

Dropped files

PID
Process
Filename
Type
3272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3272.44862\UltraISO 9.7.6.3810 Portable\UltraISOPortable\App\AppInfo\appicon.icoimage
MD5:A213A102C5C392DB46BBF6AC1D0B02AD
SHA256:D58A375BB92F312CD1031E9AF31AF9E15DC7BC02C0322F10A039D99BE7547F42
3272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3272.44862\UltraISO 9.7.6.3810 Portable\Muchos Portables!!!! -.urlurl
MD5:EA3755B22FC8DFF0C051EDE0F21F4D94
SHA256:894932952F9AF3520ED210322CCFFF9770E86A1E8FDBFC7E7A5B89DBCF03EC33
3272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3272.44862\UltraISO 9.7.6.3810 Portable\UltraISOPortable\App\UltraISO\drivers\IsoCmd.exeexecutable
MD5:26BFF94BABB8A0CCB74BCDBBA7A67F82
SHA256:28D530F9E46C6FC9FA66C4F7F232C57B3D5D9287840C13E187D513358ED12A5D
3272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3272.44862\UltraISO 9.7.6.3810 Portable\UltraISOPortable\App\UltraISO\lang\lang_ar.dllexecutable
MD5:7C8E2887FD539E53B6F34B03E5CB874E
SHA256:A065E06C2A92510F13165A84B15B191F1477CFB61D68E374ECE1A42FA8365242
3272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3272.44862\UltraISO 9.7.6.3810 Portable\UltraISOPortable\App\UltraISO\drivers\ISODrive.sysexecutable
MD5:791FB13F95502D48E1BC4225AE416F9D
SHA256:3963E8449B0261D01A4EEDF9C6B513859F04B7B82DC2FF58BE4392684AAD1A06
3272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3272.44862\UltraISO 9.7.6.3810 Portable\UltraISOPortable\App\UltraISO\drivers\FileDlg.exeexecutable
MD5:254B79698A02E3641EB77244E053DF39
SHA256:9692F519F7D1587CEFB8E26CFB25DB59304788EAE83C36000F7D162F13EBE05B
3272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3272.44862\UltraISO 9.7.6.3810 Portable\UltraISOPortable\App\AppInfo\appinfo.iniini
MD5:E3F6641A1E4F887FC354A1BDC6C6B4EE
SHA256:EB4F570710E80167785DB957CB76D788AC022E543373E9A1AADA32A27230467F
3272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3272.44862\UltraISO 9.7.6.3810 Portable\UltraISOPortable\App\UltraISO\drivers\bootpart.sysexecutable
MD5:F33F220FB53EA4B6FB7382677090116B
SHA256:851C0391EBFF61781263E9959DF9463F79A84B9908848BF8732E53E4531618E8
3272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3272.44862\UltraISO 9.7.6.3810 Portable\UltraISOPortable\App\UltraISO\lame_enc.dllexecutable
MD5:B9E34AE6D6ECB1E19B36DC70E7EF406C
SHA256:3B8817FAD300FD729D28CA4895D9FB131CF64E699FE5DE658AE44C6D056DACE4
3272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3272.44862\UltraISO 9.7.6.3810 Portable\UltraISOPortable\App\UltraISO\drivers\ISODrv64.sysexecutable
MD5:07E315C8F16DBCB642C01516B2A74470
SHA256:B38FEC15DD32E0AF8165954CF3953A5A1A1BBCA9421486B209AA65F0BE4ED0F2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
43
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1768
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5656
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5656
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2056
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6796
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
1768
svchost.exe
40.126.32.140:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1768
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
5436
svchost.exe
184.28.89.167:443
go.microsoft.com
AKAMAI-AS
US
whitelisted
6796
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
whitelisted
google.com
  • 172.217.16.206
whitelisted
www.microsoft.com
  • 88.221.169.152
  • 184.30.21.171
whitelisted
login.live.com
  • 40.126.32.140
  • 20.190.160.14
  • 40.126.32.72
  • 40.126.32.138
  • 20.190.160.20
  • 40.126.32.74
  • 40.126.32.133
  • 20.190.160.22
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
slscr.update.microsoft.com
  • 13.85.23.86
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted

Threats

No threats detected
No debug info