| download: | UDP-Unicorn.zip |
| Full analysis: | https://app.any.run/tasks/2e350c19-fa1b-4704-8240-bf0fd64540f6 |
| Verdict: | Malicious activity |
| Analysis date: | June 30, 2019, 02:04:08 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 5E8CF6C1FC7BC08BF567CE6FD94B87DE |
| SHA1: | 0A38187057E3194CA60C51F3BB681889B3052387 |
| SHA256: | 8B287FABECFE9A02B9AC2388C36893FDC77B3DB2B0CEDE9D68B7DDF408FD2C3F |
| SSDEEP: | 12288:TLam59FrmnGohJUupf2USjXpP9KhF2U7KIuvUpP5Q6E9cR9N7t:T9BrAGMf2FP9GX7KIu2hQ6McXD |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2011:04:09 12:36:27 |
| ZipCRC: | 0xf10ddad5 |
| ZipCompressedSize: | 179848 |
| ZipUncompressedSize: | 416768 |
| ZipFileName: | UDP Unicorn.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2776 | "C:\Users\admin\Desktop\UDP Unicorn.exe" | C:\Users\admin\Desktop\UDP Unicorn.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3288 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\UDP-Unicorn.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3456 | "C:\Users\admin\Desktop\UDP Unicorn.exe" | C:\Users\admin\Desktop\UDP Unicorn.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\UDP-Unicorn.zip | |||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\notepad.exe,-469 |
Value: Text Document | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3288 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3288.29135\UDP Unicorn.exe | executable | |
MD5:26A781F1B4D7A9BA041A4DA1CF90E2C7 | SHA256:216B185FC945F2C612322061844F5428606891A2AB180BE5EBACCA1FF8360F65 | |||
| 3288 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3288.29135\data\config.ini | text | |
MD5:0B8D0FEB3083A640849E6C49B129F4EB | SHA256:C9CA9EAED980532D7260B9622AEC08FD735192D394319DE6EE93DCFFB8F0B32D | |||
| 3288 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3288.29135\src\GNU General Public License.txt | text | |
MD5:52B22F4A0358441EB5D028D7C6B93787 | SHA256:E3F98636A55E83CBBD81583941AA9D1ECB5DAFFEBC72713C339DA2A1C1DA2364 | |||
| 3288 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3288.29135\src\main.c | text | |
MD5:7DFD03F966B12545BA244085F8C601DB | SHA256:5612CFC5AD1E22013CE52E059216A0ACE50A6ECD329C175C52ADC883D034D526 | |||
| 3288 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3288.29135\src\music.h | text | |
MD5:739AABBDFDFF76F2A06BA8DB2D0F5B12 | SHA256:C56BD47D5232B413DC0CEC8E75566E64D00E0C23864A7B37CBBCFEDA8DA31231 | |||
| 3288 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3288.29135\src\ps.c | text | |
MD5:4D6314576FD453F5855F4A8A801A4A25 | SHA256:ADCC61AFED98829627A5E13883ED9C15942D020BC4C26CB676EC408E4A5C9EA3 | |||
| 3288 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3288.29135\src\resource.h | text | |
MD5:62FB22015FA998225DF284D23B6EB41A | SHA256:73B84E686F1D164624060A926B434CC764CA525232FED92D3319D49576CF51C9 | |||
| 3288 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3288.29135\src\icons\music.ico | image | |
MD5:E3F842BE9699212F486FD8D0429652BC | SHA256:2560A09BB9520DC2CD3BD91DBDCA1E8E5D150D4A0B7616E8BA9C9DDCE5F811D7 | |||
| 3288 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3288.29135\src\UDPUnicorn.exe.manifest | xml | |
MD5:F2EB83FA0D8223F29EABB0A38F029CEE | SHA256:C66924787820D1604D9A7F017BEF40DDDCF84EE109AB7776EB696DAEB8EB463A | |||
| 3288 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3288.29135\src\resource.rc | text | |
MD5:DC77DB09961C162226C0248DAE93D8F5 | SHA256:751A6351B3121FDA4D39E31508C9357011C8162FF2BEB76893346E61EB74B02C | |||