File name:

malware.zip

Full analysis: https://app.any.run/tasks/be3bf799-9628-498d-9397-661b55bb9942
Verdict: Malicious activity
Threats:

Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email.

Analysis date: July 27, 2020, 10:15:25
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
autoit
trojan
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

7092969B07AC18B3CB44BD79F4937A90

SHA1:

B2D57D8E0860A81B82CF925C129FC8A50160C407

SHA256:

9CF2E4C7C4AC8CB9974B624D0B4BE6DF81FCEAB3588FAAF6745C7A9998E8C98B

SSDEEP:

196608:HXM+ATsIaY4mhcX71+/gwbr76+D0qqvqcuKIG6UG9GWIZI5lD8z789uNtCq:HXM+44mh6+pS+D0HyLPGP08I7D9ujl

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • UQiDong.exe (PID: 2904)
      • UQiDong.exe (PID: 3276)
    • Connects to CnC server

      • UQiDong.exe (PID: 3276)
  • SUSPICIOUS

    • Application launched itself

      • UQiDong.exe (PID: 2904)
    • Reads Internet Cache Settings

      • UQiDong.exe (PID: 3276)
  • INFO

    • Manual execution by user

      • UQiDong.exe (PID: 2904)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2020:07:27 11:03:14
ZipCRC: 0x01d6e7c1
ZipCompressedSize: 11846295
ZipUncompressedSize: 11999040
ZipFileName: UQiDong.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
3
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs uqidong.exe no specs uqidong.exe

Process information

PID
CMD
Path
Indicators
Parent process
2904"C:\Users\admin\Desktop\UQiDong.exe" C:\Users\admin\Desktop\UQiDong.exeexplorer.exe
User:
admin
Company:
UQiDong.Com
Integrity Level:
MEDIUM
Description:
U启动增强版
Exit code:
0
Version:
7.0.20.604
Modules
Images
c:\users\admin\desktop\uqidong.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
2960"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\malware.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3276"C:\Users\admin\Desktop\UQiDong.exe" !C:\Users\admin\Desktop\UQiDong.exe
UQiDong.exe
User:
admin
Company:
UQiDong.Com
Integrity Level:
HIGH
Description:
U启动增强版
Exit code:
0
Version:
7.0.20.604
Modules
Images
c:\users\admin\desktop\uqidong.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
Total events
390
Read events
357
Write events
33
Delete events
0

Modification events

(PID) Process:(2960) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2960) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2960) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\132\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2960) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\malware.zip
(PID) Process:(2960) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2960) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2960) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2960) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2960) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(2960) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
0
Suspicious files
0
Text files
39
Unknown types
0

Dropped files

PID
Process
Filename
Type
2960WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2960.29016\UQiDong.exe
MD5:
SHA256:
3276UQiDong.exeC:\Users\admin\AppData\Local\Temp\autDC85.tmp
MD5:
SHA256:
3276UQiDong.exeC:\Users\admin\AppData\Local\Temp\3276dzijugv
MD5:
SHA256:
3276UQiDong.exeC:\Users\admin\AppData\Local\Temp\autDE1D.tmp
MD5:
SHA256:
3276UQiDong.exeC:\Users\admin\AppData\Local\Temp\autDE3D.tmp
MD5:
SHA256:
3276UQiDong.exeC:\Users\admin\AppData\Local\Temp\autDE4E.tmp
MD5:
SHA256:
3276UQiDong.exeC:\Users\admin\AppData\Local\Temp\autDE4F.tmp
MD5:
SHA256:
3276UQiDong.exeC:\Users\admin\AppData\Local\Temp\autDE5F.tmp
MD5:
SHA256:
3276UQiDong.exeC:\Users\admin\AppData\Local\Temp\autDE70.tmp
MD5:
SHA256:
3276UQiDong.exeC:\Users\admin\AppData\Local\Temp\autDE71.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3276
UQiDong.exe
GET
200
120.132.17.169:80
http://yun.uqidong.com/UQDKefu.txt
CN
text
533 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3276
UQiDong.exe
120.132.17.169:80
yun.uqidong.com
AS Number for CHINANET jiangsu province backbone
CN
malicious

DNS requests

Domain
IP
Reputation
yun.uqidong.com
  • 120.132.17.169
malicious

Threats

PID
Process
Class
Message
3276
UQiDong.exe
Potential Corporate Privacy Violation
ET POLICY Autoit Windows Automation tool User-Agent in HTTP Request - Possibly Hostile
3276
UQiDong.exe
A Network Trojan was detected
AV TROJAN QQ Registration through AutoIT - CnC Response
No debug info