download:

/files/file/1/download/alcor-u2-mp-v19041500-b16a-b17a_d08/

Full analysis: https://app.any.run/tasks/e1c94f1b-5b9e-4752-bdf8-54e74cc08ee7
Verdict: Malicious activity
Analysis date: January 26, 2025, 00:07:18
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

B6757AE95EA06BD563A27F4AABAD26DF

SHA1:

4624B8652E8D40420953A614CCC943A26622991F

SHA256:

C9FF8EB52F005AEF6E89BDFF493ACF3EA0AC2984AD51794BB29C8B660754E625

SSDEEP:

98304:CPdR5jtMEMO60fuK0nLPF/UI7zntkFlcTBrpdy6XnMQMranc1E/X+91vp98GF+Ss:aCFw0tp9QtWNh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 512)
      • LoadDrv.exe (PID: 6808)
    • Creates file in the systems drive root

      • AlcorMP.exe (PID: 6692)
    • Executable content was dropped or overwritten

      • LoadDrv.exe (PID: 6808)
    • Creates files in the driver directory

      • LoadDrv.exe (PID: 6808)
    • There is functionality for taking screenshot (YARA)

      • AlcorMP.exe (PID: 6692)
  • INFO

    • The sample compiled with chinese language support

      • WinRAR.exe (PID: 512)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 512)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 512)
      • LoadDrv.exe (PID: 6808)
    • Checks supported languages

      • KillBaboon.exe (PID: 6732)
      • AlcorMP.exe (PID: 6692)
      • LoadDrv.exe (PID: 6752)
      • LoadDrv.exe (PID: 6808)
      • DrvCovEx.exe (PID: 6864)
      • KillBaboon.exe (PID: 6872)
      • AlcorMP.exe (PID: 7140)
      • AlcFmt.exe (PID: 7012)
      • VerifyCat.exe (PID: 6920)
    • Manual execution by a user

      • AlcorMP.exe (PID: 6640)
      • AlcorMP.exe (PID: 6692)
      • AlcFmt.exe (PID: 7012)
      • AlcorMP.exe (PID: 7092)
      • AlcorMP.exe (PID: 7140)
    • Reads the computer name

      • AlcorMP.exe (PID: 6692)
      • LoadDrv.exe (PID: 6808)
      • DrvCovEx.exe (PID: 6864)
      • AlcorMP.exe (PID: 7140)
    • Reads the software policy settings

      • VerifyCat.exe (PID: 6920)
    • Create files in a temporary directory

      • VerifyCat.exe (PID: 6920)
    • Reads the machine GUID from the registry

      • VerifyCat.exe (PID: 6920)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)

EXIF

ZIP

FileVersion: 7z v0.04
ModifyDate: 2020:05:02 13:47:29+00:00
ArchivedFileName: ALCOR U2 MP v19.04.15.00 B16A B17A
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
17
Malicious processes
0
Suspicious processes
3

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs alcormp.exe no specs alcormp.exe killbaboon.exe no specs loaddrv.exe no specs conhost.exe no specs loaddrv.exe conhost.exe no specs drvcovex.exe no specs killbaboon.exe no specs verifycat.exe no specs conhost.exe no specs alcfmt.exe no specs conhost.exe no specs alcormp.exe no specs alcormp.exe

Process information

PID
CMD
Path
Indicators
Parent process
512"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\alcor-u2-mp-v19041500-b16a-b17a_d08.7zC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6596C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
6640"C:\Users\admin\Desktop\ALCOR U2 MP v19.04.15.00 B16A B17A\AlcorMP.exe" C:\Users\admin\Desktop\ALCOR U2 MP v19.04.15.00 B16A B17A\AlcorMP.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
MP
Exit code:
3221226540
Version:
3, 1, 1, 33
Modules
Images
c:\users\admin\desktop\alcor u2 mp v19.04.15.00 b16a b17a\alcormp.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6692"C:\Users\admin\Desktop\ALCOR U2 MP v19.04.15.00 B16A B17A\AlcorMP.exe" C:\Users\admin\Desktop\ALCOR U2 MP v19.04.15.00 B16A B17A\AlcorMP.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
MP
Version:
3, 1, 1, 33
Modules
Images
c:\users\admin\desktop\alcor u2 mp v19.04.15.00 b16a b17a\alcormp.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\setupapi.dll
6732"C:\Users\admin\Desktop\ALCOR U2 MP v19.04.15.00 B16A B17A\\DRIVERS\KillBaboon.exe"C:\Users\admin\Desktop\ALCOR U2 MP v19.04.15.00 B16A B17A\DRIVERS\KillBaboon.exeAlcorMP.exe
User:
admin
Integrity Level:
HIGH
Description:
KillBaboon
Version:
1, 2, 0, 0
Modules
Images
c:\users\admin\desktop\alcor u2 mp v19.04.15.00 b16a b17a\drivers\killbaboon.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6752"C:\Users\admin\Desktop\ALCOR U2 MP v19.04.15.00 B16A B17A\drivers\LoadDrv.exe" SetIgnoreHwID 058f6387C:\Users\admin\Desktop\ALCOR U2 MP v19.04.15.00 B16A B17A\DRIVERS\LoadDrv.exeAlcorMP.exe
User:
admin
Company:
ALCOR
Integrity Level:
HIGH
Description:
LoadDrv
Exit code:
0
Version:
1, 2, 0, 0
Modules
Images
c:\users\admin\desktop\alcor u2 mp v19.04.15.00 b16a b17a\drivers\loaddrv.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6760\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeLoadDrv.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6808"C:\Users\admin\Desktop\ALCOR U2 MP v19.04.15.00 B16A B17A\drivers\LoadDrv.exe" InstByIniC:\Users\admin\Desktop\ALCOR U2 MP v19.04.15.00 B16A B17A\DRIVERS\LoadDrv.exe
AlcorMP.exe
User:
admin
Company:
ALCOR
Integrity Level:
HIGH
Description:
LoadDrv
Exit code:
0
Version:
1, 2, 0, 0
Modules
Images
c:\users\admin\desktop\alcor u2 mp v19.04.15.00 b16a b17a\drivers\loaddrv.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6816\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeLoadDrv.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6864C:\WINDOWS\system32\DrvCovEx.exe RegisterOnly DrvCovExC:\Windows\SysWOW64\DrvCovEx.exeLoadDrv.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\windows\syswow64\drvcovex.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
8 634
Read events
8 611
Write events
23
Delete events
0

Modification events

(PID) Process:(512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\alcor-u2-mp-v19041500-b16a-b17a_d08.7z
(PID) Process:(512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(512) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
Executable files
32
Suspicious files
13
Text files
267
Unknown types
0

Dropped files

PID
Process
Filename
Type
512WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa512.36491\ALCOR U2 MP v19.04.15.00 B16A B17A\flashlist.aflbinary
MD5:1D48BAD23C2A81969EE7334334CB66A3
SHA256:F19801F9B7B91BA7BC56773DA6EB5B6AF8E73D9B489EB967E58ED25E55DD184E
512WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa512.36491\ALCOR U2 MP v19.04.15.00 B16A B17A\UfdApi\UfdApi_Gen\CTL\28\BIN\28_0C_L06B_TP.BINtext
MD5:579A949DDB1218A6E18D169656B30E78
SHA256:BEA331AC46269DBC40C9F4F5B72B4B9450E51F1E4E188F5836077714CC869EFF
512WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa512.36491\ALCOR U2 MP v19.04.15.00 B16A B17A\FlashList.inibinary
MD5:9A5216A5137FAC86BE192387A36410C4
SHA256:C29A8AC2F950918B45715CDD90B94830EBDA0FE002B81A1809ABE7DA5840FA10
512WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa512.36491\ALCOR U2 MP v19.04.15.00 B16A B17A\DRIVERS\BackMp.catbinary
MD5:0AE58B2F6F109240B81E626CD0E5C137
SHA256:79BB3DB8720E5B60D20581897377569316C479493E8777A09B1F2054B89E1CFF
512WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa512.36491\ALCOR U2 MP v19.04.15.00 B16A B17A\DRIVERS\CatSetting.initext
MD5:A5087171A86654CE35201CEB6653AF14
SHA256:784F1CB69D7428425707DE38CC47E97BCB63D9682A622F92B4682D60291930A9
512WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa512.36491\ALCOR U2 MP v19.04.15.00 B16A B17A\FlashList.dattext
MD5:D211356E46C4B16FC7DC97F4DB38ABF3
SHA256:56C0C0B4B4C91E0232C71C1D4321159784F416F0A2F78FCA6FC9A053A36CD112
512WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa512.36491\ALCOR U2 MP v19.04.15.00 B16A B17A\AUTORUN\9384.imgbinary
MD5:08F9BCB981C3018B18AC8D7DFF51D822
SHA256:7239FF04D41997F048CB6C9B42D2DEAC2D2B7AFCD7296B180AEB4B63C25D9ABB
512WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa512.36491\ALCOR U2 MP v19.04.15.00 B16A B17A\HtmlFile.dattext
MD5:AA27D3760D65DAF85DA6B95B62701C4D
SHA256:F70DF5C163F78FABC63699AD1161C888FFCA28D84193B08E2F4B52790A1DC963
512WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa512.36491\ALCOR U2 MP v19.04.15.00 B16A B17A\AU698X MP user's manual_Chinese.pdfpdf
MD5:2E0E8192CBD52D9D1E369D2C2555A127
SHA256:BC5943224F643234924B3D83F71C98FC3CEA43B8EA5CD1EB99DD46EF78BAE37A
512WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa512.36491\ALCOR U2 MP v19.04.15.00 B16A B17A\UfdApi\UfdApi_Gen\CTL\28\BIN\28_17_16K_UCG256.BINtext
MD5:4CF0BD5791DA6E569C55051A0054B58B
SHA256:B821F1EE25C17CC5ED0FE521AD392A67A1E19A5F5B52FF9DAB2C067C5F2C8611
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
33
DNS requests
4
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
104.126.37.139:443
www.bing.com
Akamai International B.V.
DE
whitelisted
104.126.37.131:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:137
whitelisted
876
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3976
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
192.168.100.165:49690
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
whitelisted
www.bing.com
  • 104.126.37.139
  • 104.126.37.131
whitelisted
google.com
  • 142.250.185.110
whitelisted

Threats

No threats detected
No debug info