download: | /files/file/1/download/alcor-u2-mp-v19041500-b16a-b17a_d08/ |
Full analysis: | https://app.any.run/tasks/e9d890d4-4d3d-4bf0-955f-84bc0d345653 |
Verdict: | Malicious activity |
Analysis date: | January 26, 2025, 00:29:29 |
OS: | Windows 10 Professional (build: 19045, 64 bit) |
Tags: | |
Indicators: | |
MIME: | application/x-7z-compressed |
File info: | 7-zip archive data, version 0.4 |
MD5: | B6757AE95EA06BD563A27F4AABAD26DF |
SHA1: | 4624B8652E8D40420953A614CCC943A26622991F |
SHA256: | C9FF8EB52F005AEF6E89BDFF493ACF3EA0AC2984AD51794BB29C8B660754E625 |
SSDEEP: | 98304:CPdR5jtMEMO60fuK0nLPF/UI7zntkFlcTBrpdy6XnMQMranc1E/X+91vp98GF+Ss:aCFw0tp9QtWNh |
.7z | | | 7-Zip compressed archive (v0.4) (57.1) |
---|---|---|
.7z | | | 7-Zip compressed archive (gen) (42.8) |
FileVersion: | 7z v0.04 |
---|---|
ModifyDate: | 2020:05:02 13:47:29+00:00 |
ArchivedFileName: | ALCOR U2 MP v19.04.15.00 B16A B17A |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
624 | "C:\Users\admin\Desktop\ALCOR U2 MP v19.04.15.00 B16A B17A\drivers\LoadDrv.exe" SetIgnoreHwID 058f6387 | C:\Users\admin\Desktop\ALCOR U2 MP v19.04.15.00 B16A B17A\DRIVERS\LoadDrv.exe | — | AlcorMP.exe | |||||||||||
User: admin Company: ALCOR Integrity Level: HIGH Description: LoadDrv Exit code: 0 Version: 1, 2, 0, 0 Modules
| |||||||||||||||
936 | C:\WINDOWS\system32\DrvCovEx.exe RegisterOnly DrvCovEx | C:\Windows\SysWOW64\DrvCovEx.exe | — | LoadDrv.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
1156 | "C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\ALCOR U2 MP v19.04.15.00 B16A B17A\AlcorMP.ini | C:\Windows\System32\notepad.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
1356 | "C:\Users\admin\Desktop\ALCOR U2 MP v19.04.15.00 B16A B17A\\DRIVERS\KillBaboon.exe" | C:\Users\admin\Desktop\ALCOR U2 MP v19.04.15.00 B16A B17A\DRIVERS\KillBaboon.exe | — | AlcorMP.exe | |||||||||||
User: admin Integrity Level: HIGH Description: KillBaboon Version: 1, 2, 0, 0 Modules
| |||||||||||||||
1468 | "C:\Users\admin\Desktop\ALCOR U2 MP v19.04.15.00 B16A B17A\AlcorMP.exe" | C:\Users\admin\Desktop\ALCOR U2 MP v19.04.15.00 B16A B17A\AlcorMP.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: MP Exit code: 3221226540 Version: 3, 1, 1, 33 Modules
| |||||||||||||||
1852 | "C:\Users\admin\Desktop\ALCOR U2 MP v19.04.15.00 B16A B17A\AlcFmt.exe" | C:\Users\admin\Desktop\ALCOR U2 MP v19.04.15.00 B16A B17A\AlcFmt.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 2 Modules
| |||||||||||||||
2160 | "C:\Users\admin\Desktop\ALCOR U2 MP v19.04.15.00 B16A B17A\AlcorMP.exe" | C:\Users\admin\Desktop\ALCOR U2 MP v19.04.15.00 B16A B17A\AlcorMP.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: MP Version: 3, 1, 1, 33 Modules
| |||||||||||||||
3188 | "C:\Users\admin\Desktop\ALCOR U2 MP v19.04.15.00 B16A B17A\AutoMP.exe" | C:\Users\admin\Desktop\ALCOR U2 MP v19.04.15.00 B16A B17A\AutoMP.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: AutoMP Microsoft 基础类应用程序 Version: 1, 0, 0, 1 Modules
| |||||||||||||||
3260 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | LoadDrv.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
3260 | "C:\Users\admin\Desktop\ALCOR U2 MP v19.04.15.00 B16A B17A\\AlcorMP.exe" -AT:0005048A | C:\Users\admin\Desktop\ALCOR U2 MP v19.04.15.00 B16A B17A\AlcorMP.exe | — | AutoMP.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: MP Exit code: 3221226540 Version: 3, 1, 1, 33 Modules
|
(PID) Process: | (5560) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
(PID) Process: | (5560) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
(PID) Process: | (5560) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
(PID) Process: | (5560) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\Downloads\alcor-u2-mp-v19041500-b16a-b17a_d08.7z | |||
(PID) Process: | (5560) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (5560) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (5560) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (5560) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (5560) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths |
Operation: | write | Name: | name |
Value: 256 | |||
(PID) Process: | (5560) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths |
Operation: | write | Name: | size |
Value: 80 |
PID | Process | Filename | Type | |
---|---|---|---|---|
5560 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa5560.19444\ALCOR U2 MP v19.04.15.00 B16A B17A\AlcorMP.ini | text | |
MD5:D5F6BC4865E865E788F5B6CCBBB55F39 | SHA256:0D9E4AB9514CA51925E3AF30C41661A34E0E7E90088280E6F36A1AD764C11A79 | |||
5560 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa5560.19444\ALCOR U2 MP v19.04.15.00 B16A B17A\AUTORUN\9384.img | binary | |
MD5:08F9BCB981C3018B18AC8D7DFF51D822 | SHA256:7239FF04D41997F048CB6C9B42D2DEAC2D2B7AFCD7296B180AEB4B63C25D9ABB | |||
5560 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa5560.19444\ALCOR U2 MP v19.04.15.00 B16A B17A\flashlist.afl | binary | |
MD5:1D48BAD23C2A81969EE7334334CB66A3 | SHA256:F19801F9B7B91BA7BC56773DA6EB5B6AF8E73D9B489EB967E58ED25E55DD184E | |||
5560 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa5560.19444\ALCOR U2 MP v19.04.15.00 B16A B17A\DRIVERS\BackMp.cat | binary | |
MD5:0AE58B2F6F109240B81E626CD0E5C137 | SHA256:79BB3DB8720E5B60D20581897377569316C479493E8777A09B1F2054B89E1CFF | |||
5560 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa5560.19444\ALCOR U2 MP v19.04.15.00 B16A B17A\AUTORUN\Reserve.img | binary | |
MD5:9F0B3CFC69D17A67B7B0AE7EA93BC57C | SHA256:3E4001500F6ECFC1AF63E8286DA31E17730457B03D0E5718A619C1FA0FAE33F7 | |||
5560 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa5560.19444\ALCOR U2 MP v19.04.15.00 B16A B17A\DRIVERS\CatSetting.ini | text | |
MD5:A5087171A86654CE35201CEB6653AF14 | SHA256:784F1CB69D7428425707DE38CC47E97BCB63D9682A622F92B4682D60291930A9 | |||
5560 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa5560.19444\ALCOR U2 MP v19.04.15.00 B16A B17A\FlashList.ini | binary | |
MD5:9A5216A5137FAC86BE192387A36410C4 | SHA256:C29A8AC2F950918B45715CDD90B94830EBDA0FE002B81A1809ABE7DA5840FA10 | |||
5560 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa5560.19444\ALCOR U2 MP v19.04.15.00 B16A B17A\FlashList.dat | text | |
MD5:D211356E46C4B16FC7DC97F4DB38ABF3 | SHA256:56C0C0B4B4C91E0232C71C1D4321159784F416F0A2F78FCA6FC9A053A36CD112 | |||
5560 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa5560.19444\ALCOR U2 MP v19.04.15.00 B16A B17A\AU698X MP user's manual_Chinese.pdf | ||
MD5:2E0E8192CBD52D9D1E369D2C2555A127 | SHA256:BC5943224F643234924B3D83F71C98FC3CEA43B8EA5CD1EB99DD46EF78BAE37A | |||
5560 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa5560.19444\ALCOR U2 MP v19.04.15.00 B16A B17A\AlcorMP.cfg | text | |
MD5:F4BA0B8C9057DE6C9E07AD45B03FCB9B | SHA256:374403C7A14667DD4321D58AED8B32102C84074ADEEB6943F385733C1F2CDE6D |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3976 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5208 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 192.168.100.206:49687 | — | — | — | unknown |
Domain | IP | Reputation |
---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
dns.msftncsi.com |
| whitelisted |