File name:

umbrella.zip

Full analysis: https://app.any.run/tasks/48001bea-423e-41a4-a3f7-c939bde5e0aa
Verdict: Malicious activity
Analysis date: May 30, 2020, 14:14:03
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

6097BD0FFA7A3A021F02E301983250BE

SHA1:

88E02B8CF22B9261F7C00D8047B05FFE166C1113

SHA256:

3A8EF6126814CA02F9440DEE890706428628AC67E1401F9D2726AE99447E0772

SSDEEP:

393216:AEaXZMbLkezb7whzk3/L1rnIj3nCEQefAvUwx:yXOfkezfxL1rIjSEQWBa

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • UmbrellaInstaller.exe (PID: 3880)
      • UmbrellaInstaller.exe (PID: 2852)
      • UmbrellaInstaller.exe (PID: 2384)
      • UmbrellaInstaller.exe (PID: 3204)
    • Loads dropped or rewritten executable

      • UmbrellaInstaller.exe (PID: 2852)
      • UmbrellaInstaller.exe (PID: 3204)
    • Loads the Task Scheduler DLL interface

      • UmbrellaInstaller.exe (PID: 2852)
      • UmbrellaInstaller.exe (PID: 3204)
    • Changes settings of System certificates

      • UmbrellaInstaller.exe (PID: 2852)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • UmbrellaInstaller.exe (PID: 2852)
      • WinRAR.exe (PID: 3244)
      • UmbrellaInstaller.exe (PID: 3204)
    • Creates files in the user directory

      • UmbrellaInstaller.exe (PID: 3204)
      • UmbrellaInstaller.exe (PID: 2852)
    • Adds / modifies Windows certificates

      • UmbrellaInstaller.exe (PID: 2852)
  • INFO

    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 3128)
      • MsiExec.exe (PID: 3968)
    • Manual execution by user

      • UmbrellaInstaller.exe (PID: 3880)
      • UmbrellaInstaller.exe (PID: 2384)
      • UmbrellaInstaller.exe (PID: 3204)
      • UmbrellaInstaller.exe (PID: 2852)
    • Application launched itself

      • msiexec.exe (PID: 3360)
    • Reads settings of System Certificates

      • UmbrellaInstaller.exe (PID: 2852)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2020:05:16 14:33:06
ZipCRC: 0x68a66cbf
ZipCompressedSize: 13997165
ZipUncompressedSize: 15305448
ZipFileName: UmbrellaInstaller.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
8
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe umbrellainstaller.exe no specs umbrellainstaller.exe msiexec.exe no specs msiexec.exe no specs umbrellainstaller.exe no specs umbrellainstaller.exe msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2384"C:\Users\admin\Desktop\UmbrellaInstaller.exe" C:\Users\admin\Desktop\UmbrellaInstaller.exeexplorer.exe
User:
admin
Company:
uc.zone
Integrity Level:
MEDIUM
Description:
Umbrella Loader Installer
Exit code:
3221226540
Version:
1.0.0
Modules
Images
c:\users\admin\desktop\umbrellainstaller.exe
c:\systemroot\system32\ntdll.dll
2852"C:\Users\admin\Desktop\UmbrellaInstaller.exe" C:\Users\admin\Desktop\UmbrellaInstaller.exe
explorer.exe
User:
admin
Company:
uc.zone
Integrity Level:
HIGH
Description:
Umbrella Loader Installer
Exit code:
1603
Version:
1.0.0
Modules
Images
c:\users\admin\desktop\umbrellainstaller.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3128C:\Windows\system32\MsiExec.exe -Embedding 24D79953E9A78CA0A17DA724C10F03A8 CC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3204"C:\Users\admin\Desktop\UmbrellaInstaller.exe" C:\Users\admin\Desktop\UmbrellaInstaller.exe
explorer.exe
User:
admin
Company:
uc.zone
Integrity Level:
HIGH
Description:
Umbrella Loader Installer
Exit code:
1603
Version:
1.0.0
Modules
Images
c:\users\admin\desktop\umbrellainstaller.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3244"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\umbrella.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3360C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3880"C:\Users\admin\Desktop\UmbrellaInstaller.exe" C:\Users\admin\Desktop\UmbrellaInstaller.exeexplorer.exe
User:
admin
Company:
uc.zone
Integrity Level:
MEDIUM
Description:
Umbrella Loader Installer
Exit code:
3221226540
Version:
1.0.0
Modules
Images
c:\users\admin\desktop\umbrellainstaller.exe
c:\systemroot\system32\ntdll.dll
3968C:\Windows\system32\MsiExec.exe -Embedding D0B24334962729C4B66E52E1715C575F CC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
1 904
Read events
689
Write events
1 215
Delete events
0

Modification events

(PID) Process:(3244) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3244) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3244) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3244) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(3244) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\umbrella.zip
(PID) Process:(3244) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3244) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3244) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3244) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3244) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
12
Suspicious files
0
Text files
132
Unknown types
0

Dropped files

PID
Process
Filename
Type
2852UmbrellaInstaller.exeC:\Users\admin\AppData\Roaming\uc.zone\Umbrella Loader 1.0.0\install\holder0.aiph
MD5:
SHA256:
2852UmbrellaInstaller.exeC:\Users\admin\AppData\Local\Temp\MSI54DF.tmp
MD5:
SHA256:
2852UmbrellaInstaller.exeC:\Users\admin\AppData\Local\Temp\MSI557C.tmp
MD5:
SHA256:
2852UmbrellaInstaller.exeC:\Users\admin\AppData\Local\Temp\MSI558D.tmp
MD5:
SHA256:
2852UmbrellaInstaller.exeC:\Users\admin\AppData\Roaming\uc.zone\Umbrella Loader 1.0.0\install\decoder.dllexecutable
MD5:
SHA256:
2852UmbrellaInstaller.exeC:\Users\admin\AppData\Roaming\uc.zone\Umbrella Loader 1.0.0\install\68D1BE4\UmbrellaLoader.msiexecutable
MD5:
SHA256:
3244WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3244.41704\UmbrellaInstaller.exeexecutable
MD5:
SHA256:
2852UmbrellaInstaller.exeC:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_2852\metrorunapplicationbuttonimage
MD5:49AD8E9164FD6FACB8A8BFD6F62972B8
SHA256:914A0241A557591DFDCF3ED1EF0E557CEB153F32C716C53D13342DC5318BBB79
2852UmbrellaInstaller.exeC:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_2852\backgroundimage
MD5:A0EFB0E7B9CEE25B09E09A1A64E96BA6
SHA256:F044F542BC46464054084C63596877F06C6E2C215C0E954C4ACE9787CED82787
2852UmbrellaInstaller.exeC:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_2852\repairicimage
MD5:2ED3D45BC22B79DB09136513AED402DD
SHA256:4A8FA6335720D3E4F464AF244364923E741605B8AD3E1E28411F494E95EC11E4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info