File name:

UDP Unicorn.rar

Full analysis: https://app.any.run/tasks/ff6f1d5f-0ee1-4137-8b9e-defd8a8d19b9
Verdict: Malicious activity
Analysis date: August 02, 2021, 23:09:13
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

0BC15C9B5339CE06B06A996620480CFC

SHA1:

90B5DC14B00310CBEC0E2FB364353D4A48D2C633

SHA256:

98C29E2AA86574E617D0E73E050FDB2DF45F2230BBB76923DD64EA2F395CEE33

SSDEEP:

24576:NmFlDJP00lM0RK8i0hgZ17T0GbmFlDJP00ladhxnDN1WPxmzu9f3a:NmFlDJ00lMt7TxmFlDJ00ladDDNuxf9i

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 2116)
    • Application was dropped or rewritten from another process

      • UDP Unicorn.exe (PID: 3620)
      • Launcher.exe (PID: 2652)
      • Windows Services.exe (PID: 596)
      • Runtime Explorer.exe (PID: 3652)
      • Secure System Shell.exe (PID: 3708)
      • udpc.exe (PID: 2772)
      • Runtime Explorer.exe (PID: 2888)
    • Writes to a start menu file

      • Launcher.exe (PID: 2652)
    • Changes the autorun value in the registry

      • Launcher.exe (PID: 2652)
    • Drops executable file immediately after starts

      • Launcher.exe (PID: 2652)
  • SUSPICIOUS

    • Checks supported languages

      • WinRAR.exe (PID: 3980)
      • UDP Unicorn.exe (PID: 3620)
      • Launcher.exe (PID: 2652)
      • Windows Services.exe (PID: 596)
      • Runtime Explorer.exe (PID: 3652)
      • Secure System Shell.exe (PID: 3708)
      • powershell.exe (PID: 2956)
      • Runtime Explorer.exe (PID: 2888)
      • udpc.exe (PID: 2772)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3980)
      • Launcher.exe (PID: 2652)
    • Reads the computer name

      • WinRAR.exe (PID: 3980)
      • UDP Unicorn.exe (PID: 3620)
      • Launcher.exe (PID: 2652)
      • powershell.exe (PID: 2956)
      • Windows Services.exe (PID: 596)
      • Secure System Shell.exe (PID: 3708)
      • udpc.exe (PID: 2772)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 3980)
      • Launcher.exe (PID: 2652)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 3980)
    • Executes PowerShell scripts

      • Launcher.exe (PID: 2652)
    • Reads the date of Windows installation

      • powershell.exe (PID: 2956)
    • Creates files in the user directory

      • Launcher.exe (PID: 2652)
      • powershell.exe (PID: 2956)
    • Creates files in the Windows directory

      • Launcher.exe (PID: 2652)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • WinRAR.exe (PID: 3980)
      • Launcher.exe (PID: 2652)
    • Manual execution by user

      • UDP Unicorn.exe (PID: 3620)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
10
Malicious processes
7
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start winrar.exe searchprotocolhost.exe no specs udp unicorn.exe no specs launcher.exe powershell.exe no specs windows services.exe no specs secure system shell.exe no specs runtime explorer.exe no specs udpc.exe runtime explorer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
596"C:\Windows\IMF\Windows Services.exe" {Arguments If Needed}C:\Windows\IMF\Windows Services.exeLauncher.exe
User:
admin
Integrity Level:
HIGH
Description:
Windows Services
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\windows\imf\windows services.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\sspicli.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
2116"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2652"C:\Users\admin\Desktop\UDP Unicorn\bp\Launcher.exe" C:\Users\admin\Desktop\UDP Unicorn\bp\Launcher.exe
UDP Unicorn.exe
User:
admin
Integrity Level:
HIGH
Description:
Launcher
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\udp unicorn\bp\launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
2772"C:\Users\admin\Desktop\UDP Unicorn\bp\udpc.exe" C:\Users\admin\Desktop\UDP Unicorn\bp\udpc.exe
UDP Unicorn.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\udp unicorn\bp\udpc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2888"C:\Windows\IMF\Runtime Explorer.exe" C:\Windows\IMF\Runtime Explorer.exeWindows Services.exe
User:
admin
Company:
Control Service
Integrity Level:
HIGH
Exit code:
0
Version:
1.00
Modules
Images
c:\windows\imf\runtime explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2956"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" add-mppreference -exclusionpath C:\Windows\IMF\C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeLauncher.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\atl.dll
3620"C:\Users\admin\Desktop\UDP Unicorn\UDP Unicorn.exe" C:\Users\admin\Desktop\UDP Unicorn\UDP Unicorn.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Launcher
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\udp unicorn\udp unicorn.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3652"C:\Windows\IMF\Runtime Explorer.exe" C:\Windows\IMF\Runtime Explorer.exeWindows Services.exe
User:
admin
Company:
Control Service
Integrity Level:
HIGH
Exit code:
0
Version:
1.00
Modules
Images
c:\windows\imf\runtime explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3708"C:\Windows\IMF\Secure System Shell.exe" C:\Windows\IMF\Secure System Shell.exeWindows Services.exe
User:
admin
Integrity Level:
HIGH
Description:
Secure System Shell
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\windows\imf\secure system shell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
3980"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\UDP Unicorn.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
4 034
Read events
3 933
Write events
101
Delete events
0

Modification events

(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3980) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\UDP Unicorn.rar
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2116) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
12
Suspicious files
4
Text files
48
Unknown types
3

Dropped files

PID
Process
Filename
Type
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\Runtime Explorer.exeexecutable
MD5:
SHA256:
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\data\config.initext
MD5:0B8D0FEB3083A640849E6C49B129F4EB
SHA256:C9CA9EAED980532D7260B9622AEC08FD735192D394319DE6EE93DCFFB8F0B32D
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\Secure System Shell.exeexecutable
MD5:2D4198BDE4531CD7BC5BF51F7386ECD5
SHA256:3D68615AE56E8DBE0D60E675CC8B6AD487E541F2E4DC8202F9F450E0F416D039
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\src\ac.htext
MD5:11A8025BB692F373DFA19FAEA2E77F93
SHA256:CACEA47E1320ACFB11D3210E8810D5F9EB3F8E255A8E6B0F3C303326EFEFCE02
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\Launcher.exeexecutable
MD5:
SHA256:
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\data\music.mp3mp3
MD5:DC5A7EB6BD42DE84D271064F8DCE3136
SHA256:5022F98DF94FDA97DC74B9DC5E5414552B560CB10F46DD238BE24B7B8D7DAA65
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\src\ac.ctext
MD5:5F8CC2E104431C32B971AEEB31D0C223
SHA256:9EA9D77F95A521F2F471CBBA7A2B3DEC68DED7D6DC0DE27B276A7E2FD9613EB1
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\src\music.ctext
MD5:1C6417CEC85F38710DC82BCC17B7E698
SHA256:27EEC7A5F4DE138C46F9CBD7025E5EB66E56808108050C13B8A7D6ED7EF64B8D
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\src\icons\music.icoimage
MD5:E3F842BE9699212F486FD8D0429652BC
SHA256:2560A09BB9520DC2CD3BD91DBDCA1E8E5D150D4A0B7616E8BA9C9DDCE5F811D7
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\src\icons\idle.icoimage
MD5:E12A30CA6CC8B35395AF755880DC8746
SHA256:29FCEDBB916E14120BDDB655E345079786EA81164596FC3840C3ECBB67F38285
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info