| File name: | 26120.5722_amd64_en-us_professional_6093b451_convert.zip |
| Full analysis: | https://app.any.run/tasks/83485878-bd7d-4c74-9509-9aadaf88b9c7 |
| Verdict: | Malicious activity |
| Analysis date: | July 29, 2025, 23:56:22 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
| MD5: | 56B61EDC44A2968EC481C0AE8962E040 |
| SHA1: | 46793FCF3DD2866C9AECDA0C1287DF63CE1DF9B0 |
| SHA256: | 391BD13EB6CC997F5D4D5611BA24BBC6C0E925435E38294906483D9E3F73BDF4 |
| SSDEEP: | 192:n5BbpolgO1kHqQAOFsO1kHqQAOF1ztpNxtrDPKOLgHOt55RYe1B48NH8vksy:nrbpoqoQsoQ1VxL/DvYe1B48NH8vksy |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0002 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2025:07:29 23:46:12 |
| ZipCRC: | 0xf5585c7b |
| ZipCompressedSize: | 1766 |
| ZipUncompressedSize: | 5222 |
| ZipFileName: | uup_download_windows.cmd |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1212 | C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\Downloads\uup_download_windows.cmd" " | C:\Windows\System32\cmd.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1520 | powershell -NoProfile Start-Process -FilePath 'C:\WINDOWS\system32\cmd.exe' -ArgumentList '/c """"""C:\Users\admin\Downloads\uup_download_windows.cmd""" 49127c4b-02dc-482e-ac4f-ec4d659b7547"""' -Verb RunAs | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1612 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2120 | REG QUERY HKU\S-1-5-19\Environment | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Console Tool Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2200 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2532 | C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding | C:\Windows\System32\rundll32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3480 | C:\WINDOWS\system32\cmd.exe /c findstr #UUPDUMP_ERROR: "files\aria2_script.25394.txt" | C:\Windows\System32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3556 | powershell -NoProfile -ExecutionPolicy Unrestricted .\files\get_aria2.ps1 | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4580 | "files\aria2c.exe" --no-conf --async-dns=false --console-log-level=warn --log-level=info --log="aria2_download.log" -x16 -s16 -j2 -c -R -d"files" -i"files\converter_windows" | C:\Users\admin\Downloads\files\aria2c.exe | cmd.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 4832 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (5456) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (5456) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (5456) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (5456) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (5456) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (5456) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\26120.5722_amd64_en-us_professional_6093b451_convert.zip | |||
| (PID) Process: | (5456) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (5456) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (5456) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (5456) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5456 | WinRAR.exe | C:\Users\admin\Downloads\uup_download_macos.sh | text | |
MD5:0D51F885D7007A76A54FFC428F593F8A | SHA256:316F0D0BC76223F541354BA93B9674F408C6AE438CB296150EF35D9BB05E4E31 | |||
| 5456 | WinRAR.exe | C:\Users\admin\Downloads\files\convert_config_linux | text | |
MD5:0F802038B21E07556124EEF30A64DA20 | SHA256:DFD83DF824C5E34B2E402FD176F714D62BB512BE8CB2DD07CF530F5E51F23AE7 | |||
| 5456 | WinRAR.exe | C:\Users\admin\Downloads\files\converter_multi | text | |
MD5:52547B1827909A2DCD77083F4E31F841 | SHA256:A4EAE7918ED6CE3DD43AD47A39C9D5E0F06AD80C5F2F1CA52FE113D60827DCEF | |||
| 5456 | WinRAR.exe | C:\Users\admin\Downloads\ConvertConfig.ini | ini | |
MD5:06A5D2DAA2E225856DE9FB8D943659DC | SHA256:84A6B66226F3795C4A2C2EC694E6500A704CD156C96261AF3B2BADDD7B41BB85 | |||
| 5456 | WinRAR.exe | C:\Users\admin\Downloads\files\get_aria2.ps1 | text | |
MD5:55BD4DCBB931E1592C2E74F426522895 | SHA256:4CB3B3A9149D7DEDFB71796DED682A097DEE2454DC6B40FF95E0B33D022DB4A6 | |||
| 5456 | WinRAR.exe | C:\Users\admin\Downloads\files\convert_config_macos | text | |
MD5:0F802038B21E07556124EEF30A64DA20 | SHA256:DFD83DF824C5E34B2E402FD176F714D62BB512BE8CB2DD07CF530F5E51F23AE7 | |||
| 4580 | aria2c.exe | C:\Users\admin\Downloads\files\7zr.exe.aria2__temp | pi2 | |
MD5:2AD9DDE4EAA15CEEBB57CF703656AAE0 | SHA256:82540C8173F283D25E08E52F4B279C084AE331CB7CBF78ACA07791FEC98DF763 | |||
| 1520 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive | binary | |
MD5:B3BE74AE3404BBE59FE4897E73C2EC62 | SHA256:7CC29414BD360FD26C8FE0A7A0314835E092790EA1A79E91CF03D5DF2B3A46A3 | |||
| 5456 | WinRAR.exe | C:\Users\admin\Downloads\CustomAppsList.txt | text | |
MD5:FBF61CF1243B9D8BA4D7AAE6925A2896 | SHA256:1F2FBC910A0F016EAD61D1FEEF41D1E7B75E234753572AE37C83D0DAE955CC94 | |||
| 3556 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_tfnh1psu.du4.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6936 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | GET | 200 | 23.48.23.143:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
764 | lsass.exe | GET | 200 | 172.217.18.99:80 | http://c.pki.goog/r/gsr1.crl | unknown | — | — | whitelisted |
764 | lsass.exe | GET | 200 | 172.217.18.99:80 | http://c.pki.goog/r/r4.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 208.89.74.17:80 | http://tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/1ecfcc76-9aef-4b21-8fa3-658208d65849?P1=1753833974&P2=404&P3=2&P4=Qw5sGPJ7zd1b17LYOXQ5jZdkj%2bzpwapszVnpJiq%2f6tEvnUJKJHIMcXS0b2ZhkbgK%2fSRUW%2bMQK9FrZrvDevSPPw%3d%3d | unknown | — | — | whitelisted |
— | — | GET | 200 | 208.89.74.17:80 | http://tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/226423f2-75c1-4af3-b215-5c6550300289?P1=1753833974&P2=404&P3=2&P4=kS7j%2fPUQ727Rq%2fb4ljzS6JZ%2fu9Z9n1e0T%2frx1W2zjxA14cWIYcB5YupSd8u8u0gWm2ojYpASz3geGVddQxRnsA%3d%3d | unknown | — | — | whitelisted |
7164 | aria2c.exe | GET | 200 | 208.89.74.17:80 | http://tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/fcf46846-4554-4fae-aca2-d746349a9420?P1=1753833974&P2=404&P3=2&P4=nZlsAPj5%2bAM7eUsbDy16sKMAIz8W6FB1Qql6ZPGPyklFgwTPFhG7nkup5utnk7%2bS7Nu9Xbgm%2b9dYTgmNa52tpg%3d%3d | unknown | — | — | whitelisted |
7164 | aria2c.exe | GET | 200 | 208.89.74.17:80 | http://tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/be56d69b-cfb1-493c-9339-04fb7ae2e5c5?P1=1753833974&P2=404&P3=2&P4=D49VFZCUfvZT8oNguJiRpHnwOKvBKNeMUlmKR5CMlNvipCVDSWZb9PEJlRATY9gXnE01NMmWbHBlACVzSYoa2g%3d%3d | unknown | — | — | whitelisted |
7164 | aria2c.exe | GET | 200 | 208.89.74.17:80 | http://tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/c1c8098c-affc-4907-ba91-1028a6718ce6?P1=1753833974&P2=404&P3=2&P4=Yg%2bKtfnVmcU6d1xhLAaIpyt0dRItGJ8EKTlgWMbNkIjre2eaa8S%2fSf38QAk4lqMZ2Ii6uHYbGh7GO37e3DEs%2bg%3d%3d | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1268 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1040 | RUXIMICS.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6936 | svchost.exe | 20.190.160.22:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6936 | svchost.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
5944 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5944 | MoUsoCoreWorker.exe | 23.48.23.143:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
5944 | MoUsoCoreWorker.exe | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
uupdump.net |
| malicious |
client.wns.windows.com |
| whitelisted |
c.pki.goog |
| whitelisted |
tlu.dl.delivery.mp.microsoft.com |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
7164 | aria2c.exe | A Network Trojan was detected | ET USER_AGENTS Aria2 User-Agent |
7164 | aria2c.exe | A Network Trojan was detected | ET USER_AGENTS Aria2 User-Agent |
7164 | aria2c.exe | A Network Trojan was detected | ET USER_AGENTS Aria2 User-Agent |
7164 | aria2c.exe | A Network Trojan was detected | ET USER_AGENTS Aria2 User-Agent |
7164 | aria2c.exe | A Network Trojan was detected | ET USER_AGENTS Aria2 User-Agent |
7164 | aria2c.exe | A Network Trojan was detected | ET USER_AGENTS Aria2 User-Agent |
7164 | aria2c.exe | A Network Trojan was detected | ET USER_AGENTS Aria2 User-Agent |
7164 | aria2c.exe | A Network Trojan was detected | ET USER_AGENTS Aria2 User-Agent |
7164 | aria2c.exe | A Network Trojan was detected | ET USER_AGENTS Aria2 User-Agent |
7164 | aria2c.exe | A Network Trojan was detected | ET USER_AGENTS Aria2 User-Agent |