File name:

UltraISO_9.7.6.3810_Portable.rar

Full analysis: https://app.any.run/tasks/4ce9ae99-8cdd-4118-bdfa-24eb5243bb3d
Verdict: Malicious activity
Analysis date: October 02, 2024, 20:40:26
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

16A8C08F8E5226E6A804C9F0B5065B04

SHA1:

181454BED596A41C3327C4C8D34757DDA72360F1

SHA256:

1BB89E7E6097D051787054530177C3E607BCF95F88DA8E2E7F4F4DEF3982DFC8

SSDEEP:

98304:YgLXeRoxhXsn2NjEtPujtVsB7l+0PFmkohWr3PN36/P2PEzOMZ+ouDxsOWG58IRG:SWta27

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 3272)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • UltraISOPortable.exe (PID: 6324)
      • UltraISOPortable.exe (PID: 6644)
    • Executable content was dropped or overwritten

      • UltraISOPortable.exe (PID: 6324)
      • UltraISOPortable.exe (PID: 6644)
    • Application launched itself

      • UltraISOPortable.exe (PID: 6324)
    • Uses REG/REGEDIT.EXE to modify registry

      • UltraISOPortable.exe (PID: 6644)
  • INFO

    • Manual execution by a user

      • UltraISOPortable.exe (PID: 6324)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3272)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
134
Monitored processes
7
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe ultraisoportable.exe ultraisoportable.exe regedit.exe no specs isocmd.exe no specs conhost.exe no specs ultraiso.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3272"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\UltraISO_9.7.6.3810_Portable.rarC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3648\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeIsoCmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5700"C:\Users\admin\Desktop\UltraISO 9.7.6.3810 Portable\UltraISOPortable\App\UltraISO\UltraISO.exe" /UAC:110330 /NCRCC:\Users\admin\Desktop\UltraISO 9.7.6.3810 Portable\UltraISOPortable\App\UltraISO\UltraISO.exeUltraISOPortable.exe
User:
admin
Company:
EZB Systems, Inc.
Integrity Level:
HIGH
Description:
UltraISO Premium
Version:
9.7.6.3810
Modules
Images
c:\users\admin\desktop\ultraiso 9.7.6.3810 portable\ultraisoportable\app\ultraiso\ultraiso.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\setupapi.dll
6324"C:\Users\admin\Desktop\UltraISO 9.7.6.3810 Portable\UltraISOPortable\UltraISOPortable.exe" C:\Users\admin\Desktop\UltraISO 9.7.6.3810 Portable\UltraISOPortable\UltraISOPortable.exe
explorer.exe
User:
admin
Company:
9649
Integrity Level:
MEDIUM
Description:
UltraISO Premium
Version:
2.2.1.0
Modules
Images
c:\users\admin\desktop\ultraiso 9.7.6.3810 portable\ultraisoportable\ultraisoportable.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6576"C:\WINDOWS\regedit.exe" /s "C:\Users\admin\Desktop\UltraISO 9.7.6.3810 Portable\UltraISOPortable\Data\settings\UltraISO.reg"C:\Windows\SysWOW64\regedit.exeUltraISOPortable.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Editor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regedit.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6644"C:\Users\admin\Desktop\UltraISO 9.7.6.3810 Portable\UltraISOPortable\UltraISOPortable.exe" /UAC:110330 /NCRC C:\Users\admin\Desktop\UltraISO 9.7.6.3810 Portable\UltraISOPortable\UltraISOPortable.exe
UltraISOPortable.exe
User:
admin
Company:
9649
Integrity Level:
HIGH
Description:
UltraISO Premium
Version:
2.2.1.0
Modules
Images
c:\users\admin\desktop\ultraiso 9.7.6.3810 portable\ultraisoportable\ultraisoportable.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7028"C:\Users\admin\Desktop\UltraISO 9.7.6.3810 Portable\UltraISOPortable\App\UltraISO\drivers\IsoCmd.exe" -iC:\Users\admin\Desktop\UltraISO 9.7.6.3810 Portable\UltraISOPortable\App\UltraISO\drivers\IsoCmd.exeUltraISOPortable.exe
User:
admin
Company:
EZB Systems, Inc.
Integrity Level:
HIGH
Description:
ISO Command
Exit code:
0
Version:
3.20 built by: WinDDK
Modules
Images
c:\users\admin\desktop\ultraiso 9.7.6.3810 portable\ultraisoportable\app\ultraiso\drivers\isocmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
Total events
3 654
Read events
2 446
Write events
498
Delete events
710

Modification events

(PID) Process:(3272) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(3272) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\UltraISO_9.7.6.3810_Portable.rar
(PID) Process:(3272) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3272) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3272) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3272) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3272) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(3272) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
(PID) Process:(3272) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3272) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:psize
Value:
80
Executable files
58
Suspicious files
2
Text files
11
Unknown types
0

Dropped files

PID
Process
Filename
Type
3272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3272.44862\UltraISO 9.7.6.3810 Portable\Muchos Portables!!!! -.urlurl
MD5:EA3755B22FC8DFF0C051EDE0F21F4D94
SHA256:894932952F9AF3520ED210322CCFFF9770E86A1E8FDBFC7E7A5B89DBCF03EC33
3272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3272.44862\UltraISO 9.7.6.3810 Portable\UltraISOPortable\App\AppInfo\appinfo.iniini
MD5:E3F6641A1E4F887FC354A1BDC6C6B4EE
SHA256:EB4F570710E80167785DB957CB76D788AC022E543373E9A1AADA32A27230467F
3272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3272.44862\UltraISO 9.7.6.3810 Portable\UltraISOPortable\App\AppInfo\Launcher\UltraISOPortable.iniini
MD5:DD1103F680BD3987DCFA9600B5020131
SHA256:D41EA1B2C94F72BAD4DC768EC024CD2830665EEB10F278472A6C79929074CCF7
3272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3272.44862\UltraISO 9.7.6.3810 Portable\UltraISOPortable\App\AppInfo\Launcher\Custom.nshtext
MD5:EBE7D149032BA844B1109D9DE7AE309A
SHA256:D7A0870842F4740749504A941EB7D9BCA2D33489378F53B0667EF366C0C1F782
3272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3272.44862\UltraISO 9.7.6.3810 Portable\UltraISOPortable\App\UltraISO\drivers\bootpart.sysexecutable
MD5:F33F220FB53EA4B6FB7382677090116B
SHA256:851C0391EBFF61781263E9959DF9463F79A84B9908848BF8732E53E4531618E8
3272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3272.44862\UltraISO 9.7.6.3810 Portable\UltraISOPortable\App\UltraISO\drivers\bootpt64.sysexecutable
MD5:2833318575DDAE3921B9BBCF5186F6D9
SHA256:96943D7B3FBCE92403392A2A8A31C3BE89C65F78E6A6D248EB16D120E46F1F1A
3272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3272.44862\UltraISO 9.7.6.3810 Portable\UltraISOPortable\App\UltraISO\drivers\ISODrv64.sysexecutable
MD5:07E315C8F16DBCB642C01516B2A74470
SHA256:B38FEC15DD32E0AF8165954CF3953A5A1A1BBCA9421486B209AA65F0BE4ED0F2
3272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3272.44862\UltraISO 9.7.6.3810 Portable\UltraISOPortable\App\DefaultData\settings\UltraISO.regtext
MD5:1C6CDEE6820CF41320DF4CEB25FE7F60
SHA256:606EC68B9F8ADADA233AA38D3EB7BA596DB50CBA9141E7A58B7CCDB74C2A2AA5
3272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3272.44862\UltraISO 9.7.6.3810 Portable\UltraISOPortable\App\UltraISO\drivers\ISODrive.sysexecutable
MD5:791FB13F95502D48E1BC4225AE416F9D
SHA256:3963E8449B0261D01A4EEDF9C6B513859F04B7B82DC2FF58BE4392684AAD1A06
3272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3272.44862\UltraISO 9.7.6.3810 Portable\UltraISOPortable\App\UltraISO\drivers\IsoCmd.exeexecutable
MD5:26BFF94BABB8A0CCB74BCDBBA7A67F82
SHA256:28D530F9E46C6FC9FA66C4F7F232C57B3D5D9287840C13E187D513358ED12A5D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
43
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1768
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5656
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5656
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2056
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6796
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
1768
svchost.exe
40.126.32.140:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1768
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
5436
svchost.exe
184.28.89.167:443
go.microsoft.com
AKAMAI-AS
US
whitelisted
6796
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
whitelisted
google.com
  • 172.217.16.206
whitelisted
www.microsoft.com
  • 88.221.169.152
  • 184.30.21.171
whitelisted
login.live.com
  • 40.126.32.140
  • 20.190.160.14
  • 40.126.32.72
  • 40.126.32.138
  • 20.190.160.20
  • 40.126.32.74
  • 40.126.32.133
  • 20.190.160.22
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
slscr.update.microsoft.com
  • 13.85.23.86
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted

Threats

No threats detected
No debug info