download:

UDP-Unicorn.zip

Full analysis: https://app.any.run/tasks/fd90c6da-ebca-4592-9d81-05cfe12a5558
Verdict: Malicious activity
Threats:

Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying.

Analysis date: June 30, 2019, 02:14:51
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
ransomware
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

5E8CF6C1FC7BC08BF567CE6FD94B87DE

SHA1:

0A38187057E3194CA60C51F3BB681889B3052387

SHA256:

8B287FABECFE9A02B9AC2388C36893FDC77B3DB2B0CEDE9D68B7DDF408FD2C3F

SSDEEP:

12288:TLam59FrmnGohJUupf2USjXpP9KhF2U7KIuvUpP5Q6E9cR9N7t:T9BrAGMf2FP9GX7KIu2hQ6McXD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • UDP Unicorn.exe (PID: 676)
      • UDP Unicorn.exe (PID: 1840)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2916)
  • INFO

    • Manual execution by user

      • UDP Unicorn.exe (PID: 676)
      • UDP Unicorn.exe (PID: 1840)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2011:04:09 12:36:27
ZipCRC: 0xf10ddad5
ZipCompressedSize: 179848
ZipUncompressedSize: 416768
ZipFileName: UDP Unicorn.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe udp unicorn.exe udp unicorn.exe

Process information

PID
CMD
Path
Indicators
Parent process
676"C:\Users\admin\Desktop\UDP Unicorn.exe" C:\Users\admin\Desktop\UDP Unicorn.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\udp unicorn.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1840"C:\Users\admin\Desktop\UDP Unicorn.exe" C:\Users\admin\Desktop\UDP Unicorn.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\udp unicorn.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2916"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\UDP-Unicorn.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
450
Read events
429
Write events
21
Delete events
0

Modification events

(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2916) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\UDP-Unicorn.zip
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2916) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
1
Suspicious files
0
Text files
24
Unknown types
1

Dropped files

PID
Process
Filename
Type
2916WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2916.42449\src\config.ctext
MD5:7A9B1FF10E8A104D425C6E72C69A72E5
SHA256:09D207B76B0B46E985C415C6E721D683D260483C75F8EA1C1C3642AB09A00A9F
2916WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2916.42449\src\music.htext
MD5:739AABBDFDFF76F2A06BA8DB2D0F5B12
SHA256:C56BD47D5232B413DC0CEC8E75566E64D00E0C23864A7B37CBBCFEDA8DA31231
2916WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2916.42449\src\config.htext
MD5:02C6DD430244DD320F73B2786AACF7E6
SHA256:C7F3B1A548764FC5E5170A6A9B45E01250284BD791B1D3DEE7684E46B4B4756F
2916WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2916.42449\src\ac.ctext
MD5:5F8CC2E104431C32B971AEEB31D0C223
SHA256:9EA9D77F95A521F2F471CBBA7A2B3DEC68DED7D6DC0DE27B276A7E2FD9613EB1
2916WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2916.42449\src\icons\mainicon.icoimage
MD5:86E05A25555E37CF590A552E52FEE462
SHA256:588647ADF722E241746C7949A0CEA50F2704C795513C8F701690CF6874B4E4A8
2916WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2916.42449\src\GNU General Public License.txttext
MD5:52B22F4A0358441EB5D028D7C6B93787
SHA256:E3F98636A55E83CBBD81583941AA9D1ECB5DAFFEBC72713C339DA2A1C1DA2364
2916WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2916.42449\src\ps.ctext
MD5:4D6314576FD453F5855F4A8A801A4A25
SHA256:ADCC61AFED98829627A5E13883ED9C15942D020BC4C26CB676EC408E4A5C9EA3
2916WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2916.42449\src\icons\attacking.icoimage
MD5:FD085EEAD12C8AA1F303318B4654A613
SHA256:971C1D0C83C6AA72950ED0D54E23D9DF802174ABBC0A6D4DCA0E28FE1716F1E6
2916WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2916.42449\src\icons\music.icoimage
MD5:E3F842BE9699212F486FD8D0429652BC
SHA256:2560A09BB9520DC2CD3BD91DBDCA1E8E5D150D4A0B7616E8BA9C9DDCE5F811D7
2916WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2916.42449\src\main.ctext
MD5:7DFD03F966B12545BA244085F8C601DB
SHA256:5612CFC5AD1E22013CE52E059216A0ACE50A6ECD329C175C52ADC883D034D526
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info