File name:

UDP Unicorn.rar

Full analysis: https://app.any.run/tasks/ff6f1d5f-0ee1-4137-8b9e-defd8a8d19b9
Verdict: Malicious activity
Analysis date: August 02, 2021, 23:09:13
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

0BC15C9B5339CE06B06A996620480CFC

SHA1:

90B5DC14B00310CBEC0E2FB364353D4A48D2C633

SHA256:

98C29E2AA86574E617D0E73E050FDB2DF45F2230BBB76923DD64EA2F395CEE33

SSDEEP:

24576:NmFlDJP00lM0RK8i0hgZ17T0GbmFlDJP00ladhxnDN1WPxmzu9f3a:NmFlDJ00lMt7TxmFlDJ00ladDDNuxf9i

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 2116)
    • Application was dropped or rewritten from another process

      • UDP Unicorn.exe (PID: 3620)
      • Launcher.exe (PID: 2652)
      • Windows Services.exe (PID: 596)
      • Secure System Shell.exe (PID: 3708)
      • Runtime Explorer.exe (PID: 3652)
      • udpc.exe (PID: 2772)
      • Runtime Explorer.exe (PID: 2888)
    • Drops executable file immediately after starts

      • Launcher.exe (PID: 2652)
    • Changes the autorun value in the registry

      • Launcher.exe (PID: 2652)
    • Writes to a start menu file

      • Launcher.exe (PID: 2652)
  • SUSPICIOUS

    • Drops a file with too old compile date

      • WinRAR.exe (PID: 3980)
    • Reads the computer name

      • WinRAR.exe (PID: 3980)
      • UDP Unicorn.exe (PID: 3620)
      • Launcher.exe (PID: 2652)
      • powershell.exe (PID: 2956)
      • Secure System Shell.exe (PID: 3708)
      • udpc.exe (PID: 2772)
      • Windows Services.exe (PID: 596)
    • Checks supported languages

      • WinRAR.exe (PID: 3980)
      • UDP Unicorn.exe (PID: 3620)
      • Launcher.exe (PID: 2652)
      • Windows Services.exe (PID: 596)
      • Runtime Explorer.exe (PID: 2888)
      • powershell.exe (PID: 2956)
      • udpc.exe (PID: 2772)
      • Runtime Explorer.exe (PID: 3652)
      • Secure System Shell.exe (PID: 3708)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 3980)
      • Launcher.exe (PID: 2652)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3980)
      • Launcher.exe (PID: 2652)
    • Creates files in the Windows directory

      • Launcher.exe (PID: 2652)
    • Executes PowerShell scripts

      • Launcher.exe (PID: 2652)
    • Reads the date of Windows installation

      • powershell.exe (PID: 2956)
    • Creates files in the user directory

      • Launcher.exe (PID: 2652)
      • powershell.exe (PID: 2956)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • WinRAR.exe (PID: 3980)
      • Launcher.exe (PID: 2652)
    • Manual execution by user

      • UDP Unicorn.exe (PID: 3620)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
10
Malicious processes
7
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start winrar.exe searchprotocolhost.exe no specs udp unicorn.exe no specs launcher.exe powershell.exe no specs windows services.exe no specs secure system shell.exe no specs runtime explorer.exe no specs udpc.exe runtime explorer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
596"C:\Windows\IMF\Windows Services.exe" {Arguments If Needed}C:\Windows\IMF\Windows Services.exeLauncher.exe
User:
admin
Integrity Level:
HIGH
Description:
Windows Services
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\windows\imf\windows services.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\sspicli.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
2116"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2652"C:\Users\admin\Desktop\UDP Unicorn\bp\Launcher.exe" C:\Users\admin\Desktop\UDP Unicorn\bp\Launcher.exe
UDP Unicorn.exe
User:
admin
Integrity Level:
HIGH
Description:
Launcher
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\udp unicorn\bp\launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
2772"C:\Users\admin\Desktop\UDP Unicorn\bp\udpc.exe" C:\Users\admin\Desktop\UDP Unicorn\bp\udpc.exe
UDP Unicorn.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\udp unicorn\bp\udpc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2888"C:\Windows\IMF\Runtime Explorer.exe" C:\Windows\IMF\Runtime Explorer.exeWindows Services.exe
User:
admin
Company:
Control Service
Integrity Level:
HIGH
Exit code:
0
Version:
1.00
Modules
Images
c:\windows\imf\runtime explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2956"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" add-mppreference -exclusionpath C:\Windows\IMF\C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeLauncher.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\atl.dll
3620"C:\Users\admin\Desktop\UDP Unicorn\UDP Unicorn.exe" C:\Users\admin\Desktop\UDP Unicorn\UDP Unicorn.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Launcher
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\udp unicorn\udp unicorn.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3652"C:\Windows\IMF\Runtime Explorer.exe" C:\Windows\IMF\Runtime Explorer.exeWindows Services.exe
User:
admin
Company:
Control Service
Integrity Level:
HIGH
Exit code:
0
Version:
1.00
Modules
Images
c:\windows\imf\runtime explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3708"C:\Windows\IMF\Secure System Shell.exe" C:\Windows\IMF\Secure System Shell.exeWindows Services.exe
User:
admin
Integrity Level:
HIGH
Description:
Secure System Shell
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\windows\imf\secure system shell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
3980"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\UDP Unicorn.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
4 034
Read events
3 933
Write events
101
Delete events
0

Modification events

(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3980) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\UDP Unicorn.rar
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2116) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
12
Suspicious files
4
Text files
48
Unknown types
3

Dropped files

PID
Process
Filename
Type
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\Runtime Explorer.exeexecutable
MD5:
SHA256:
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\Launcher.exeexecutable
MD5:
SHA256:
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\data\config.initext
MD5:0B8D0FEB3083A640849E6C49B129F4EB
SHA256:C9CA9EAED980532D7260B9622AEC08FD735192D394319DE6EE93DCFFB8F0B32D
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\dataBaseCfg.exeexecutable
MD5:E011A24F3DA97C5D2CBEEAEEAFE72F32
SHA256:CD22A00F45D6EC40E628039C8EE1763D33496C4534C6F0E320DDFDD22BEB7880
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\data\music.mp3mp3
MD5:DC5A7EB6BD42DE84D271064F8DCE3136
SHA256:5022F98DF94FDA97DC74B9DC5E5414552B560CB10F46DD238BE24B7B8D7DAA65
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\Read Me.txttext
MD5:BE8125B099B4EE86F659CFEF04B63A1B
SHA256:3C1F2189C23C9949F1C0448FA7938427170AB2DC026D4DF159FDF76CFEB27A5C
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\src\icons\mainicon.icoimage
MD5:86E05A25555E37CF590A552E52FEE462
SHA256:588647ADF722E241746C7949A0CEA50F2704C795513C8F701690CF6874B4E4A8
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\src\icons\attacking.icoimage
MD5:FD085EEAD12C8AA1F303318B4654A613
SHA256:971C1D0C83C6AA72950ED0D54E23D9DF802174ABBC0A6D4DCA0E28FE1716F1E6
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\src\icons\music.icoimage
MD5:E3F842BE9699212F486FD8D0429652BC
SHA256:2560A09BB9520DC2CD3BD91DBDCA1E8E5D150D4A0B7616E8BA9C9DDCE5F811D7
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\src\main.ctext
MD5:7DFD03F966B12545BA244085F8C601DB
SHA256:5612CFC5AD1E22013CE52E059216A0ACE50A6ECD329C175C52ADC883D034D526
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info