File name:

Unlocker_Portable_1.9.2_32-64_Multilingual.exe

Full analysis: https://app.any.run/tasks/56abe6ed-7db2-4945-9922-213c27529a1d
Verdict: Malicious activity
Analysis date: February 06, 2024, 20:12:27
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

07C142AF7824AF8A5B4F3596B59985EC

SHA1:

3D3D58C71610E17D8322FEB35D6EDBF28ED2E17A

SHA256:

73C8E65E28C6DB79ABDF1522BEE5CB31D676F3B131ED14B1FBF52595E0741F94

SSDEEP:

6144:5FF9+2kbhtsUdytCUJN7uoad6ws44EoxGPGznMLej7LpRa4s:xObH9UNi/dVsZDxG+znMLeH1R6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Unlocker_Portable_1.9.2_32-64_Multilingual.exe (PID: 1504)
      • UnlockerPortable.exe (PID: 3584)
      • UnlockerPortable.exe (PID: 1812)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • Unlocker_Portable_1.9.2_32-64_Multilingual.exe (PID: 1504)
      • UnlockerPortable.exe (PID: 3584)
      • UnlockerPortable.exe (PID: 1812)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • Unlocker_Portable_1.9.2_32-64_Multilingual.exe (PID: 1504)
      • UnlockerPortable.exe (PID: 3584)
      • UnlockerPortable.exe (PID: 1812)
    • Drops a system driver (possible attempt to evade defenses)

      • Unlocker_Portable_1.9.2_32-64_Multilingual.exe (PID: 1504)
    • Executable content was dropped or overwritten

      • Unlocker_Portable_1.9.2_32-64_Multilingual.exe (PID: 1504)
      • UnlockerPortable.exe (PID: 3584)
      • UnlockerPortable.exe (PID: 1812)
    • Reads the Internet Settings

      • UnlockerPortable.exe (PID: 3584)
      • UnlockerPortable.exe (PID: 1812)
    • Searches for installed software

      • UnlockerAssistant.exe (PID: 3568)
      • Unlocker.exe (PID: 3572)
      • Unlocker.exe (PID: 2540)
      • UnlockerAssistant.exe (PID: 2436)
  • INFO

    • Create files in a temporary directory

      • Unlocker_Portable_1.9.2_32-64_Multilingual.exe (PID: 1504)
      • UnlockerPortable.exe (PID: 3584)
      • UnlockerPortable.exe (PID: 1812)
    • Checks supported languages

      • Unlocker_Portable_1.9.2_32-64_Multilingual.exe (PID: 1504)
      • UnlockerPortable.exe (PID: 3584)
      • UnlockerAssistant.exe (PID: 3568)
      • Unlocker.exe (PID: 3572)
      • UnlockerPortable.exe (PID: 1812)
      • UnlockerAssistant.exe (PID: 2436)
      • Unlocker.exe (PID: 2540)
    • Reads the computer name

      • Unlocker_Portable_1.9.2_32-64_Multilingual.exe (PID: 1504)
      • UnlockerPortable.exe (PID: 3584)
      • UnlockerPortable.exe (PID: 1812)
      • Unlocker.exe (PID: 3572)
      • Unlocker.exe (PID: 2540)
    • Manual execution by a user

      • UnlockerPortable.exe (PID: 2796)
      • UnlockerPortable.exe (PID: 3584)
      • UnlockerPortable.exe (PID: 3844)
      • UnlockerPortable.exe (PID: 1812)
    • Creates files or folders in the user directory

      • UnlockerPortable.exe (PID: 3584)
      • UnlockerPortable.exe (PID: 1812)
    • Reads the machine GUID from the registry

      • UnlockerPortable.exe (PID: 3584)
      • UnlockerPortable.exe (PID: 1812)
      • Unlocker.exe (PID: 2540)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (91.9)
.exe | Win32 Executable MS Visual C++ (generic) (3.3)
.exe | Win64 Executable (generic) (3)
.dll | Win32 Dynamic Link Library (generic) (0.7)
.exe | Win32 Executable (generic) (0.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:02:24 20:21:56+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 27648
InitializedDataSize: 272896
UninitializedDataSize: 8704
EntryPoint: 0x3814
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Windows, Latin1
Comments: 20/05/2013 20:14:25
CompanyName: PortableAppZ.blogspot.com
FileDescription: Unlocker Portable
FileVersion: 0.0.0.0
InternalName: Unlocker Portable
LegalCopyright: Bernat
LegalTrademarks: PortableAppZ is a Trademark of Bernat
OriginalFileName: UnlockerPortable.exe
ProductName: Unlocker Portable
ProductVersion: 0.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
10
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start unlocker_portable_1.9.2_32-64_multilingual.exe unlockerportable.exe no specs unlockerportable.exe unlockerassistant.exe no specs unlocker.exe no specs unlockerportable.exe no specs unlockerportable.exe unlockerassistant.exe no specs unlocker.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
572"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1504"C:\Users\admin\AppData\Local\Temp\Unlocker_Portable_1.9.2_32-64_Multilingual.exe" C:\Users\admin\AppData\Local\Temp\Unlocker_Portable_1.9.2_32-64_Multilingual.exe
explorer.exe
User:
admin
Company:
PortableAppZ.blogspot.com
Integrity Level:
MEDIUM
Description:
Unlocker Portable
Exit code:
0
Version:
0.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\unlocker_portable_1.9.2_32-64_multilingual.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
1812"C:\Users\admin\Desktop\UnlockerPortable\UnlockerPortable.exe" C:\Users\admin\Desktop\UnlockerPortable\UnlockerPortable.exe
explorer.exe
User:
admin
Company:
PortableAppZ.blogspot.com
Integrity Level:
HIGH
Description:
Unlocker Portable
Exit code:
0
Version:
2013.05.20.20
Modules
Images
c:\users\admin\desktop\unlockerportable\unlockerportable.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2436"C:\Users\admin\Desktop\UnlockerPortable\App\Unlocker\UnlockerAssistant.exe"C:\Users\admin\Desktop\UnlockerPortable\App\Unlocker\UnlockerAssistant.exeUnlockerPortable.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\unlockerportable\app\unlocker\unlockerassistant.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
2540"C:\Users\admin\Desktop\UnlockerPortable\App\Unlocker\Unlocker.exe" C:\Users\admin\Desktop\UnlockerPortable\App\Unlocker\Unlocker.exeUnlockerPortable.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\unlockerportable\app\unlocker\unlocker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\psapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2796"C:\Users\admin\Desktop\UnlockerPortable\UnlockerPortable.exe" C:\Users\admin\Desktop\UnlockerPortable\UnlockerPortable.exeexplorer.exe
User:
admin
Company:
PortableAppZ.blogspot.com
Integrity Level:
MEDIUM
Description:
Unlocker Portable
Exit code:
3221226540
Version:
2013.05.20.20
Modules
Images
c:\users\admin\desktop\unlockerportable\unlockerportable.exe
c:\windows\system32\ntdll.dll
3568"C:\Users\admin\Desktop\UnlockerPortable\App\Unlocker\UnlockerAssistant.exe"C:\Users\admin\Desktop\UnlockerPortable\App\Unlocker\UnlockerAssistant.exeUnlockerPortable.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\unlockerportable\app\unlocker\unlockerassistant.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
3572"C:\Users\admin\Desktop\UnlockerPortable\App\Unlocker\Unlocker.exe" C:\Users\admin\Desktop\UnlockerPortable\App\Unlocker\Unlocker.exeUnlockerPortable.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\unlockerportable\app\unlocker\unlocker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\psapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3584"C:\Users\admin\Desktop\UnlockerPortable\UnlockerPortable.exe" C:\Users\admin\Desktop\UnlockerPortable\UnlockerPortable.exe
explorer.exe
User:
admin
Company:
PortableAppZ.blogspot.com
Integrity Level:
HIGH
Description:
Unlocker Portable
Exit code:
0
Version:
2013.05.20.20
Modules
Images
c:\users\admin\desktop\unlockerportable\unlockerportable.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3844"C:\Users\admin\Desktop\UnlockerPortable\UnlockerPortable.exe" C:\Users\admin\Desktop\UnlockerPortable\UnlockerPortable.exeexplorer.exe
User:
admin
Company:
PortableAppZ.blogspot.com
Integrity Level:
MEDIUM
Description:
Unlocker Portable
Exit code:
3221226540
Version:
2013.05.20.20
Modules
Images
c:\users\admin\desktop\unlockerportable\unlockerportable.exe
c:\windows\system32\ntdll.dll
Total events
3 427
Read events
3 376
Write events
26
Delete events
25

Modification events

(PID) Process:(1504) Unlocker_Portable_1.9.2_32-64_Multilingual.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1504) Unlocker_Portable_1.9.2_32-64_Multilingual.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:Browse For Folder Width
Value:
318
(PID) Process:(1504) Unlocker_Portable_1.9.2_32-64_Multilingual.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:Browse For Folder Height
Value:
288
(PID) Process:(3584) UnlockerPortable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\PortableAppRegistryTest
Operation:delete keyName:(default)
Value:
(PID) Process:(3584) UnlockerPortable.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3584) UnlockerPortable.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3584) UnlockerPortable.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3584) UnlockerPortable.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3572) Unlocker.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3572) Unlocker.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:Browse For Folder Width
Value:
318
Executable files
25
Suspicious files
14
Text files
15
Unknown types
0

Dropped files

PID
Process
Filename
Type
1504Unlocker_Portable_1.9.2_32-64_Multilingual.exeC:\Users\admin\AppData\Local\Temp\nsc31D4.tmp\FindProcDLL.dllexecutable
MD5:8614C450637267AFACAD1645E23BA24A
SHA256:0FA04F06A6DE18D316832086891E9C23AE606D7784D5D5676385839B21CA2758
1504Unlocker_Portable_1.9.2_32-64_Multilingual.exeC:\Users\admin\AppData\Local\Temp\nsc31D4.tmp\ioSpecial.initext
MD5:E2D5070BC28DB1AC745613689FF86067
SHA256:D95AED234F932A1C48A2B1B0D98C60CA31F962310C03158E2884AB4DDD3EA1E0
1504Unlocker_Portable_1.9.2_32-64_Multilingual.exeC:\Users\admin\AppData\Local\Temp\nsc31D4.tmp\w7tbp.dllexecutable
MD5:9A3031CC4CEF0DBA236A28EECDF0AFB5
SHA256:53BB519E3293164947AC7CBD7E612F637D77A7B863E3534BA1A7E39B350D3C00
1504Unlocker_Portable_1.9.2_32-64_Multilingual.exeC:\Users\admin\Desktop\UnlockerPortable\UnlockerPortable.exeexecutable
MD5:1FF083C4E1F4716C34FF0E6D0D9E0F5F
SHA256:41F0D8422752C128B9BB8ECDEF2F9609C877262E89B7C61E0157BB9BBE2E2519
1504Unlocker_Portable_1.9.2_32-64_Multilingual.exeC:\Users\admin\AppData\Local\Temp\nsc31D4.tmp\System.dllexecutable
MD5:A78507EA1078CADAA8B2EC1A2E1D874F
SHA256:93D1E681DAEBFD24FF9FAB3952E8AE94EDDBDFB3650937988C1FD8085991610E
1504Unlocker_Portable_1.9.2_32-64_Multilingual.exeC:\Users\admin\Desktop\UnlockerPortable\App\Unlocker\Unlocker.exeexecutable
MD5:0ED06220BC07EC9A5D8807F9D5C0D9F0
SHA256:04462D02B3967614082D531D7594548C94CB4C715AE4F38203F026F211248659
1504Unlocker_Portable_1.9.2_32-64_Multilingual.exeC:\Users\admin\Desktop\UnlockerPortable\App\Unlocker64\Unlocker.exeexecutable
MD5:0A77F732624155A215F5CA54DF9B2930
SHA256:A0B651038C4301F70E4AEA506EB90EDC584A5C4CA46880C7DC2AE5EAFA6DC506
1504Unlocker_Portable_1.9.2_32-64_Multilingual.exeC:\Users\admin\Desktop\UnlockerPortable\App\Unlocker\README.TXTtext
MD5:F3B322AADB14E1B2BA9BF38972DC216C
SHA256:B604FA4D14829D2D5B55F94D9B7298417ACD0949E4F4C1483A4411BC4968AFAC
1504Unlocker_Portable_1.9.2_32-64_Multilingual.exeC:\Users\admin\Desktop\UnlockerPortable\App\Unlocker\UnlockerAssistant.exeexecutable
MD5:255E405D801CF01247390F38F92D8042
SHA256:B0A4C2B6F40D7AD177DBD40C26B579D67CC9A95552970D9F6F0C7DE372CE2A2F
1504Unlocker_Portable_1.9.2_32-64_Multilingual.exeC:\Users\admin\Desktop\UnlockerPortable\App\Unlocker\UnlockerCOM.dllexecutable
MD5:49B6AF547ED4BA1FB07BF6F384FDA841
SHA256:86E8E34CFB71100CDA06FE96573D832049CD18B1B251823139E935A1FAEFCBE8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info