File name:

udcc_launcher.zip

Full analysis: https://app.any.run/tasks/500049b7-9efe-4262-a641-6a28873e3e4c
Verdict: Malicious activity
Analysis date: November 19, 2024, 20:22:01
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

EBD4968898A1B63F53B6919F5216914E

SHA1:

4E2D1AF438A172999706C43EEA57601178781D61

SHA256:

9113C7D3038318FA243DA865283D724290E1A406AAF0B5D147504E877C7EDBD0

SSDEEP:

49152:MFTtNp9G24EOz1U1FwnxI3ez3Tt4NTjOfCKazWdWebao7qRMvYX3tPMOULJRbtrO:MF5NpA24EOz1U1FwC3GD+NWfczWdW6e1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 3208)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Manual execution by a user

      • UDCC Launcher.exe (PID: 6836)
      • UDCC Launcher.exe (PID: 6860)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3208)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:11:15 22:22:42
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: UDCC Launcher/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
132
Monitored processes
6
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe udcc launcher.exe no specs udcc launcher.exe no specs udcc launcher.exe no specs udcc launcher.exe no specs udcc launcher.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3208"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\udcc_launcher.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5656"C:\Users\admin\AppData\Local\Temp\Rar$EXa3208.5580\UDCC Launcher\UDCC Launcher.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3208.5580\UDCC Launcher\UDCC Launcher.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3208.5580\udcc launcher\udcc launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6408"C:\Users\admin\AppData\Local\Temp\Rar$EXa3208.8727\UDCC Launcher\UDCC Launcher.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3208.8727\UDCC Launcher\UDCC Launcher.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3208.8727\udcc launcher\udcc launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6732"C:\Users\admin\AppData\Local\Temp\Rar$EXa3208.11275\UDCC Launcher\UDCC Launcher.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3208.11275\UDCC Launcher\UDCC Launcher.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3208.11275\udcc launcher\udcc launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6836"C:\Users\admin\Desktop\UDCC Launcher.exe" C:\Users\admin\Desktop\UDCC Launcher.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\udcc launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6860"C:\Users\admin\Desktop\UDCC Launcher.exe" C:\Users\admin\Desktop\UDCC Launcher.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\udcc launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
2 914
Read events
2 882
Write events
32
Delete events
0

Modification events

(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\udcc_launcher.zip
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:size
Value:
80
Executable files
8
Suspicious files
4
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3208.5580\UDCC Launcher\config.initext
MD5:C1471EAE6B46AD8C0BD5CC9C33133B4A
SHA256:693BD4C0B71347FD3806512824C54040D42E464B30137B0D23383E6AEAE8477E
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3208.5580\UDCC Launcher\UDCC Launcher.exeexecutable
MD5:EF8133C607A3A4DA67DC606B9396088A
SHA256:2F7F35FB28B409FB33DD152B4FAEF937E2247D50B448D4C55B7C0993929A6507
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3208.8727\UDCC Launcher\UDCC Launcher.exeexecutable
MD5:EF8133C607A3A4DA67DC606B9396088A
SHA256:2F7F35FB28B409FB33DD152B4FAEF937E2247D50B448D4C55B7C0993929A6507
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3208.5580\UDCC Launcher\UiLib_d_x64.dllexecutable
MD5:49BB90BE6748F44AA335CBE5FDC025D8
SHA256:856D463B3EDAF591CAF07C3EE9264C7E0126837D338F4563519B1057DEBE9E3D
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3208.12739\UDCC Launcher\UDCC Launcher.exeexecutable
MD5:EF8133C607A3A4DA67DC606B9396088A
SHA256:2F7F35FB28B409FB33DD152B4FAEF937E2247D50B448D4C55B7C0993929A6507
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3208.8727\UDCC Launcher\UiLib_d_x64.dllexecutable
MD5:49BB90BE6748F44AA335CBE5FDC025D8
SHA256:856D463B3EDAF591CAF07C3EE9264C7E0126837D338F4563519B1057DEBE9E3D
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\udcc_launcher.zipcompressed
MD5:FAAC47E0A4451734CED03ADC7EC9A69D
SHA256:161777F701DBA2D0A49BCED9343A8990994F9F8D571F63C9DF93A3E0F3B1293D
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3208.12739\UDCC Launcher\UiLib_d_x64.dllexecutable
MD5:49BB90BE6748F44AA335CBE5FDC025D8
SHA256:856D463B3EDAF591CAF07C3EE9264C7E0126837D338F4563519B1057DEBE9E3D
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3208.11275\UDCC Launcher\UiLib_d_x64.dllexecutable
MD5:49BB90BE6748F44AA335CBE5FDC025D8
SHA256:856D463B3EDAF591CAF07C3EE9264C7E0126837D338F4563519B1057DEBE9E3D
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3208.12739\UDCC Launcher\config.initext
MD5:E64ACED057E539BA35583E8C88318BD7
SHA256:C8670FD1AE163400487FF3B2E6985669A81160C71B50D35F7E75A881C4DB4DDF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
34
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
2.16.241.12:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2876
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
2876
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5376
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
2.16.241.12:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4932
svchost.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
5660
RUXIMICS.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3976
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
4932
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5064
SearchApp.exe
2.23.209.140:443
www.bing.com
Akamai International B.V.
GB
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 2.16.241.12
  • 2.16.241.19
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted
google.com
  • 142.250.185.142
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
www.bing.com
  • 2.23.209.140
  • 2.23.209.182
  • 2.23.209.179
  • 2.23.209.189
  • 2.23.209.185
  • 2.23.209.133
  • 2.23.209.149
  • 2.23.209.130
  • 2.23.209.176
whitelisted
login.live.com
  • 20.190.159.68
  • 20.190.159.0
  • 20.190.159.4
  • 20.190.159.64
  • 20.190.159.73
  • 20.190.159.75
  • 20.190.159.71
  • 40.126.31.71
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted

Threats

No threats detected
No debug info