File name:

UDP Unicorn.rar

Full analysis: https://app.any.run/tasks/ff6f1d5f-0ee1-4137-8b9e-defd8a8d19b9
Verdict: Malicious activity
Analysis date: August 02, 2021, 23:09:13
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

0BC15C9B5339CE06B06A996620480CFC

SHA1:

90B5DC14B00310CBEC0E2FB364353D4A48D2C633

SHA256:

98C29E2AA86574E617D0E73E050FDB2DF45F2230BBB76923DD64EA2F395CEE33

SSDEEP:

24576:NmFlDJP00lM0RK8i0hgZ17T0GbmFlDJP00ladhxnDN1WPxmzu9f3a:NmFlDJ00lMt7TxmFlDJ00ladDDNuxf9i

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 2116)
    • Application was dropped or rewritten from another process

      • UDP Unicorn.exe (PID: 3620)
      • Launcher.exe (PID: 2652)
      • Windows Services.exe (PID: 596)
      • Runtime Explorer.exe (PID: 3652)
      • udpc.exe (PID: 2772)
      • Secure System Shell.exe (PID: 3708)
      • Runtime Explorer.exe (PID: 2888)
    • Changes the autorun value in the registry

      • Launcher.exe (PID: 2652)
    • Writes to a start menu file

      • Launcher.exe (PID: 2652)
    • Drops executable file immediately after starts

      • Launcher.exe (PID: 2652)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 3980)
      • Launcher.exe (PID: 2652)
      • UDP Unicorn.exe (PID: 3620)
      • powershell.exe (PID: 2956)
      • Windows Services.exe (PID: 596)
      • Secure System Shell.exe (PID: 3708)
      • udpc.exe (PID: 2772)
    • Checks supported languages

      • WinRAR.exe (PID: 3980)
      • Launcher.exe (PID: 2652)
      • UDP Unicorn.exe (PID: 3620)
      • powershell.exe (PID: 2956)
      • Windows Services.exe (PID: 596)
      • Runtime Explorer.exe (PID: 3652)
      • Secure System Shell.exe (PID: 3708)
      • udpc.exe (PID: 2772)
      • Runtime Explorer.exe (PID: 2888)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3980)
      • Launcher.exe (PID: 2652)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 3980)
    • Drops a file that was compiled in debug mode

      • Launcher.exe (PID: 2652)
      • WinRAR.exe (PID: 3980)
    • Executes PowerShell scripts

      • Launcher.exe (PID: 2652)
    • Creates files in the Windows directory

      • Launcher.exe (PID: 2652)
    • Creates files in the user directory

      • Launcher.exe (PID: 2652)
      • powershell.exe (PID: 2956)
    • Reads the date of Windows installation

      • powershell.exe (PID: 2956)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • WinRAR.exe (PID: 3980)
      • Launcher.exe (PID: 2652)
    • Manual execution by user

      • UDP Unicorn.exe (PID: 3620)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
10
Malicious processes
7
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs udp unicorn.exe no specs launcher.exe powershell.exe no specs windows services.exe no specs secure system shell.exe no specs runtime explorer.exe no specs udpc.exe runtime explorer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
596"C:\Windows\IMF\Windows Services.exe" {Arguments If Needed}C:\Windows\IMF\Windows Services.exeLauncher.exe
User:
admin
Integrity Level:
HIGH
Description:
Windows Services
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\windows\imf\windows services.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\sspicli.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
2116"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2652"C:\Users\admin\Desktop\UDP Unicorn\bp\Launcher.exe" C:\Users\admin\Desktop\UDP Unicorn\bp\Launcher.exe
UDP Unicorn.exe
User:
admin
Integrity Level:
HIGH
Description:
Launcher
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\udp unicorn\bp\launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
2772"C:\Users\admin\Desktop\UDP Unicorn\bp\udpc.exe" C:\Users\admin\Desktop\UDP Unicorn\bp\udpc.exe
UDP Unicorn.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\udp unicorn\bp\udpc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2888"C:\Windows\IMF\Runtime Explorer.exe" C:\Windows\IMF\Runtime Explorer.exeWindows Services.exe
User:
admin
Company:
Control Service
Integrity Level:
HIGH
Exit code:
0
Version:
1.00
Modules
Images
c:\windows\imf\runtime explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2956"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" add-mppreference -exclusionpath C:\Windows\IMF\C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeLauncher.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\atl.dll
3620"C:\Users\admin\Desktop\UDP Unicorn\UDP Unicorn.exe" C:\Users\admin\Desktop\UDP Unicorn\UDP Unicorn.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Launcher
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\udp unicorn\udp unicorn.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3652"C:\Windows\IMF\Runtime Explorer.exe" C:\Windows\IMF\Runtime Explorer.exeWindows Services.exe
User:
admin
Company:
Control Service
Integrity Level:
HIGH
Exit code:
0
Version:
1.00
Modules
Images
c:\windows\imf\runtime explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3708"C:\Windows\IMF\Secure System Shell.exe" C:\Windows\IMF\Secure System Shell.exeWindows Services.exe
User:
admin
Integrity Level:
HIGH
Description:
Secure System Shell
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\windows\imf\secure system shell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
3980"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\UDP Unicorn.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
4 034
Read events
3 933
Write events
101
Delete events
0

Modification events

(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3980) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\UDP Unicorn.rar
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2116) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
12
Suspicious files
4
Text files
48
Unknown types
3

Dropped files

PID
Process
Filename
Type
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\Runtime Explorer.exeexecutable
MD5:AC50FBB6324A3F92D4D4EECB91F137CC
SHA256:DCC738726103AD183F2CC9C6798BD7E018FD30B6C79A724D8C7EBFD08ACA07FB
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\data\config.initext
MD5:0B8D0FEB3083A640849E6C49B129F4EB
SHA256:C9CA9EAED980532D7260B9622AEC08FD735192D394319DE6EE93DCFFB8F0B32D
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\Read Me.txttext
MD5:BE8125B099B4EE86F659CFEF04B63A1B
SHA256:3C1F2189C23C9949F1C0448FA7938427170AB2DC026D4DF159FDF76CFEB27A5C
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\src\ac.ctext
MD5:5F8CC2E104431C32B971AEEB31D0C223
SHA256:9EA9D77F95A521F2F471CBBA7A2B3DEC68DED7D6DC0DE27B276A7E2FD9613EB1
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\src\ac.htext
MD5:11A8025BB692F373DFA19FAEA2E77F93
SHA256:CACEA47E1320ACFB11D3210E8810D5F9EB3F8E255A8E6B0F3C303326EFEFCE02
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\src\config.htext
MD5:02C6DD430244DD320F73B2786AACF7E6
SHA256:C7F3B1A548764FC5E5170A6A9B45E01250284BD791B1D3DEE7684E46B4B4756F
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\dataBaseCfg.exeexecutable
MD5:E011A24F3DA97C5D2CBEEAEEAFE72F32
SHA256:CD22A00F45D6EC40E628039C8EE1763D33496C4534C6F0E320DDFDD22BEB7880
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\src\netinfo.ctext
MD5:9B70286F1C5EB27349B775AC131897E6
SHA256:B954BFBEE3B2794C79DC04F09BEF62808A430DCE154581D27C10645EC07C531F
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\src\music.ctext
MD5:1C6417CEC85F38710DC82BCC17B7E698
SHA256:27EEC7A5F4DE138C46F9CBD7025E5EB66E56808108050C13B8A7D6ED7EF64B8D
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\src\music.htext
MD5:739AABBDFDFF76F2A06BA8DB2D0F5B12
SHA256:C56BD47D5232B413DC0CEC8E75566E64D00E0C23864A7B37CBBCFEDA8DA31231
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info