File name:

UDP Unicorn.rar

Full analysis: https://app.any.run/tasks/ff6f1d5f-0ee1-4137-8b9e-defd8a8d19b9
Verdict: Malicious activity
Analysis date: August 02, 2021, 23:09:13
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

0BC15C9B5339CE06B06A996620480CFC

SHA1:

90B5DC14B00310CBEC0E2FB364353D4A48D2C633

SHA256:

98C29E2AA86574E617D0E73E050FDB2DF45F2230BBB76923DD64EA2F395CEE33

SSDEEP:

24576:NmFlDJP00lM0RK8i0hgZ17T0GbmFlDJP00ladhxnDN1WPxmzu9f3a:NmFlDJ00lMt7TxmFlDJ00ladDDNuxf9i

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 2116)
    • Application was dropped or rewritten from another process

      • UDP Unicorn.exe (PID: 3620)
      • Launcher.exe (PID: 2652)
      • Windows Services.exe (PID: 596)
      • Secure System Shell.exe (PID: 3708)
      • Runtime Explorer.exe (PID: 3652)
      • udpc.exe (PID: 2772)
      • Runtime Explorer.exe (PID: 2888)
    • Drops executable file immediately after starts

      • Launcher.exe (PID: 2652)
    • Writes to a start menu file

      • Launcher.exe (PID: 2652)
    • Changes the autorun value in the registry

      • Launcher.exe (PID: 2652)
  • SUSPICIOUS

    • Checks supported languages

      • WinRAR.exe (PID: 3980)
      • UDP Unicorn.exe (PID: 3620)
      • Launcher.exe (PID: 2652)
      • powershell.exe (PID: 2956)
      • Windows Services.exe (PID: 596)
      • Runtime Explorer.exe (PID: 3652)
      • Secure System Shell.exe (PID: 3708)
      • udpc.exe (PID: 2772)
      • Runtime Explorer.exe (PID: 2888)
    • Reads the computer name

      • WinRAR.exe (PID: 3980)
      • UDP Unicorn.exe (PID: 3620)
      • Launcher.exe (PID: 2652)
      • powershell.exe (PID: 2956)
      • Windows Services.exe (PID: 596)
      • Secure System Shell.exe (PID: 3708)
      • udpc.exe (PID: 2772)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3980)
      • Launcher.exe (PID: 2652)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 3980)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 3980)
      • Launcher.exe (PID: 2652)
    • Executes PowerShell scripts

      • Launcher.exe (PID: 2652)
    • Creates files in the Windows directory

      • Launcher.exe (PID: 2652)
    • Reads the date of Windows installation

      • powershell.exe (PID: 2956)
    • Creates files in the user directory

      • Launcher.exe (PID: 2652)
      • powershell.exe (PID: 2956)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • WinRAR.exe (PID: 3980)
      • Launcher.exe (PID: 2652)
    • Manual execution by user

      • UDP Unicorn.exe (PID: 3620)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
10
Malicious processes
7
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start winrar.exe searchprotocolhost.exe no specs udp unicorn.exe no specs launcher.exe powershell.exe no specs windows services.exe no specs secure system shell.exe no specs runtime explorer.exe no specs udpc.exe runtime explorer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
596"C:\Windows\IMF\Windows Services.exe" {Arguments If Needed}C:\Windows\IMF\Windows Services.exeLauncher.exe
User:
admin
Integrity Level:
HIGH
Description:
Windows Services
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\windows\imf\windows services.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\sspicli.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
2116"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2652"C:\Users\admin\Desktop\UDP Unicorn\bp\Launcher.exe" C:\Users\admin\Desktop\UDP Unicorn\bp\Launcher.exe
UDP Unicorn.exe
User:
admin
Integrity Level:
HIGH
Description:
Launcher
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\udp unicorn\bp\launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
2772"C:\Users\admin\Desktop\UDP Unicorn\bp\udpc.exe" C:\Users\admin\Desktop\UDP Unicorn\bp\udpc.exe
UDP Unicorn.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\udp unicorn\bp\udpc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2888"C:\Windows\IMF\Runtime Explorer.exe" C:\Windows\IMF\Runtime Explorer.exeWindows Services.exe
User:
admin
Company:
Control Service
Integrity Level:
HIGH
Exit code:
0
Version:
1.00
Modules
Images
c:\windows\imf\runtime explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2956"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" add-mppreference -exclusionpath C:\Windows\IMF\C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeLauncher.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\atl.dll
3620"C:\Users\admin\Desktop\UDP Unicorn\UDP Unicorn.exe" C:\Users\admin\Desktop\UDP Unicorn\UDP Unicorn.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Launcher
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\udp unicorn\udp unicorn.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3652"C:\Windows\IMF\Runtime Explorer.exe" C:\Windows\IMF\Runtime Explorer.exeWindows Services.exe
User:
admin
Company:
Control Service
Integrity Level:
HIGH
Exit code:
0
Version:
1.00
Modules
Images
c:\windows\imf\runtime explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3708"C:\Windows\IMF\Secure System Shell.exe" C:\Windows\IMF\Secure System Shell.exeWindows Services.exe
User:
admin
Integrity Level:
HIGH
Description:
Secure System Shell
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\windows\imf\secure system shell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
3980"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\UDP Unicorn.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
4 034
Read events
3 933
Write events
101
Delete events
0

Modification events

(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3980) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\UDP Unicorn.rar
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2116) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
12
Suspicious files
4
Text files
48
Unknown types
3

Dropped files

PID
Process
Filename
Type
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\Launcher.exeexecutable
MD5:
SHA256:
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\Runtime Explorer.exeexecutable
MD5:
SHA256:
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\src\icons\idle.icoimage
MD5:E12A30CA6CC8B35395AF755880DC8746
SHA256:29FCEDBB916E14120BDDB655E345079786EA81164596FC3840C3ECBB67F38285
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\data\config.initext
MD5:0B8D0FEB3083A640849E6C49B129F4EB
SHA256:C9CA9EAED980532D7260B9622AEC08FD735192D394319DE6EE93DCFFB8F0B32D
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\dataBaseCfg.exeexecutable
MD5:E011A24F3DA97C5D2CBEEAEEAFE72F32
SHA256:CD22A00F45D6EC40E628039C8EE1763D33496C4534C6F0E320DDFDD22BEB7880
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\data\music.mp3mp3
MD5:DC5A7EB6BD42DE84D271064F8DCE3136
SHA256:5022F98DF94FDA97DC74B9DC5E5414552B560CB10F46DD238BE24B7B8D7DAA65
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\src\netinfo.ctext
MD5:9B70286F1C5EB27349B775AC131897E6
SHA256:B954BFBEE3B2794C79DC04F09BEF62808A430DCE154581D27C10645EC07C531F
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\src\config.htext
MD5:02C6DD430244DD320F73B2786AACF7E6
SHA256:C7F3B1A548764FC5E5170A6A9B45E01250284BD791B1D3DEE7684E46B4B4756F
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\src\ac.htext
MD5:11A8025BB692F373DFA19FAEA2E77F93
SHA256:CACEA47E1320ACFB11D3210E8810D5F9EB3F8E255A8E6B0F3C303326EFEFCE02
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.43124\UDP Unicorn\bp\src\GNU General Public License.txttext
MD5:52B22F4A0358441EB5D028D7C6B93787
SHA256:E3F98636A55E83CBBD81583941AA9D1ECB5DAFFEBC72713C339DA2A1C1DA2364
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info