download:

UDP-Unicorn.zip

Full analysis: https://app.any.run/tasks/2e350c19-fa1b-4704-8240-bf0fd64540f6
Verdict: Malicious activity
Analysis date: June 30, 2019, 02:04:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

5E8CF6C1FC7BC08BF567CE6FD94B87DE

SHA1:

0A38187057E3194CA60C51F3BB681889B3052387

SHA256:

8B287FABECFE9A02B9AC2388C36893FDC77B3DB2B0CEDE9D68B7DDF408FD2C3F

SSDEEP:

12288:TLam59FrmnGohJUupf2USjXpP9KhF2U7KIuvUpP5Q6E9cR9N7t:T9BrAGMf2FP9GX7KIu2hQ6McXD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • UDP Unicorn.exe (PID: 2776)
      • UDP Unicorn.exe (PID: 3456)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3288)
  • INFO

    • Manual execution by user

      • UDP Unicorn.exe (PID: 3456)
      • UDP Unicorn.exe (PID: 2776)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2011:04:09 12:36:27
ZipCRC: 0xf10ddad5
ZipCompressedSize: 179848
ZipUncompressedSize: 416768
ZipFileName: UDP Unicorn.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe udp unicorn.exe no specs udp unicorn.exe

Process information

PID
CMD
Path
Indicators
Parent process
2776"C:\Users\admin\Desktop\UDP Unicorn.exe" C:\Users\admin\Desktop\UDP Unicorn.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\udp unicorn.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3288"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\UDP-Unicorn.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3456"C:\Users\admin\Desktop\UDP Unicorn.exe" C:\Users\admin\Desktop\UDP Unicorn.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\udp unicorn.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
436
Read events
426
Write events
10
Delete events
0

Modification events

(PID) Process:(3288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3288) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\UDP-Unicorn.zip
(PID) Process:(3288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3288) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
1
Suspicious files
0
Text files
25
Unknown types
1

Dropped files

PID
Process
Filename
Type
3288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3288.29135\UDP Unicorn.exeexecutable
MD5:26A781F1B4D7A9BA041A4DA1CF90E2C7
SHA256:216B185FC945F2C612322061844F5428606891A2AB180BE5EBACCA1FF8360F65
3288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3288.29135\data\config.initext
MD5:0B8D0FEB3083A640849E6C49B129F4EB
SHA256:C9CA9EAED980532D7260B9622AEC08FD735192D394319DE6EE93DCFFB8F0B32D
3288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3288.29135\src\GNU General Public License.txttext
MD5:52B22F4A0358441EB5D028D7C6B93787
SHA256:E3F98636A55E83CBBD81583941AA9D1ECB5DAFFEBC72713C339DA2A1C1DA2364
3288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3288.29135\src\main.ctext
MD5:7DFD03F966B12545BA244085F8C601DB
SHA256:5612CFC5AD1E22013CE52E059216A0ACE50A6ECD329C175C52ADC883D034D526
3288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3288.29135\src\music.htext
MD5:739AABBDFDFF76F2A06BA8DB2D0F5B12
SHA256:C56BD47D5232B413DC0CEC8E75566E64D00E0C23864A7B37CBBCFEDA8DA31231
3288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3288.29135\src\ps.ctext
MD5:4D6314576FD453F5855F4A8A801A4A25
SHA256:ADCC61AFED98829627A5E13883ED9C15942D020BC4C26CB676EC408E4A5C9EA3
3288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3288.29135\src\resource.htext
MD5:62FB22015FA998225DF284D23B6EB41A
SHA256:73B84E686F1D164624060A926B434CC764CA525232FED92D3319D49576CF51C9
3288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3288.29135\src\icons\music.icoimage
MD5:E3F842BE9699212F486FD8D0429652BC
SHA256:2560A09BB9520DC2CD3BD91DBDCA1E8E5D150D4A0B7616E8BA9C9DDCE5F811D7
3288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3288.29135\src\UDPUnicorn.exe.manifestxml
MD5:F2EB83FA0D8223F29EABB0A38F029CEE
SHA256:C66924787820D1604D9A7F017BEF40DDDCF84EE109AB7776EB696DAEB8EB463A
3288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3288.29135\src\resource.rctext
MD5:DC77DB09961C162226C0248DAE93D8F5
SHA256:751A6351B3121FDA4D39E31508C9357011C8162FF2BEB76893346E61EB74B02C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info