File name:

UUU3021-20220212T195001Z-001.zip

Full analysis: https://app.any.run/tasks/677c4844-5a7d-4342-a49f-425ab11db9a4
Verdict: Malicious activity
Analysis date: February 12, 2022, 19:50:45
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

D655CE92F31514C96E74CC60FDA3864F

SHA1:

AF77E9CB3AECA52D4619618DFBE0F1203C47A368

SHA256:

8EA5F103F437BD0F4B27783CB362620A4631674615BAB3436F97B5AD3244AC9B

SSDEEP:

49152:1VccizYXS12GyMf5f6Lupi9bYWzYiNlvaAd0QnZaVS71ObUyMK7Vosz:1VcniS1gg6LupaYgNlva00ybOWWoS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • UuuClient.exe (PID: 1596)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 3576)
      • UuuClient.exe (PID: 1596)
    • Checks supported languages

      • WinRAR.exe (PID: 3576)
      • UuuClient.exe (PID: 1596)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3576)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 3576)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 3576)
  • INFO

    • Checks supported languages

      • WISPTIS.EXE (PID: 3776)
    • Reads the computer name

      • WISPTIS.EXE (PID: 3776)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: UUU3021/UuuClient.exe.config
ZipUncompressedSize: 614
ZipCompressedSize: 354
ZipCRC: 0x8be1d4fd
ZipModifyDate: 2020:01:26 08:58:14
ZipCompression: Deflated
ZipBitFlag: 0x0808
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
4
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start winrar.exe uuuclient.exe no specs wisptis.exe no specs wisptis.exe

Process information

PID
CMD
Path
Indicators
Parent process
1596"C:\Users\admin\AppData\Local\Temp\Rar$EXa3576.11463\UUU3021\UuuClient.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3576.11463\UUU3021\UuuClient.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Exit code:
0
Version:
3.0.2020.0128
3140"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXEUuuClient.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Pen and Touch Input Component
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3576"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\UUU3021-20220212T195001Z-001.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
3776"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXE
UuuClient.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
24
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
0
Read events
0
Write events
0
Delete events
0

Modification events

No data
Executable files
7
Suspicious files
0
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3576.11463\UUU3021\Readme.txttext
MD5:C0A3026E53DA8F2151BC08D273E6F5F9
SHA256:C1423FDD68BE3740890FD1ADE4105D9DD9010CA06D1E9610D0B4663811D362C0
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3576.11463\UUU3021\ModernWpf.Controls.dllexecutable
MD5:D79D1EE499D420144F9F8A2327D7EC0D
SHA256:3456DAD94463E71E1EE300219871172439A49C9CF9FF3F67109AEB755B5C35E1
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3576.11463\UUU3021\ToastNotifications.dllexecutable
MD5:CE4C69D4BA73105BF8EFF333FF8D265B
SHA256:ED1297117C8DBA2B3880246721AF5B74C6AE16D745BEA176ADBEEFC1EE75F2FB
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3576.11463\UUU3021\UuuClient.exeexecutable
MD5:F27ECE59B091A854A1A1D94EFF3F27AE
SHA256:22431A11497A177FCB5AA362C7A7A7EB21E1C9A27015233F750A24ABCBB730CF
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3576.11463\UUU3021\System.ValueTuple.dllexecutable
MD5:99CEC77DBEE0AB10B9FC4D52A1D414BE
SHA256:D6FB0DCFEE1490A8168117ED1B55758F11DB38475417B3668D19F89DCB55CBDD
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3576.11463\UUU3021\UuuClientSettings.iniini
MD5:DD4A44982DF97B055947399A1E089878
SHA256:8E3036960FC8C7137D6F70748582DCB6E3900BC59B98FDCBE8E33BBADD8BDED1
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3576.11463\UUU3021\UuuClient.exe.configxml
MD5:8C33C8AF4D492EA3816643EE506E6774
SHA256:8841B21C5FCFB1A27A40D928DCA98C6FCAE3528202E4834DD9431FB80397F649
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3576.11463\UUU3021\ModernWpf.dllexecutable
MD5:85B01AB1A579C52563F7CA8B750658FF
SHA256:9C5F0B80FD4B47C4D6EE4B17558C234FA1BFC3A3DEA05260AC9A41A9DBBBA9D7
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3576.11463\UUU3021\kekhack_fivem_premium.dllexecutable
MD5:FB958CBE5C964C25332B2C8346E1EC52
SHA256:E664888F61E03CB486F5DB1D5E01762488A9B4AE6927378B19E8BF7E41D39E7B
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3576.11463\UUU3021\UniversalUE4Unlocker.dllexecutable
MD5:0192098D333EE0456668A94FF75DD866
SHA256:FBE25869C37522651CD1F0DDE264A0C3CB035FD70200B55028501B0986F19519
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info