File name:

reversehub.rar

Full analysis: https://app.any.run/tasks/0c922a9c-95c5-404c-b16b-efe821ea5603
Verdict: Malicious activity
Analysis date: April 20, 2024, 09:27:25
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

2FE649F3A5FBDE9AA282E7AF35BF09F5

SHA1:

A304B219B9F60F23BC25F7F053A749906ED06A46

SHA256:

20E1D46A3C5CE3A8663CEA4B4B10E66D11E922EE3BD535C2F76B38436DE0A2FA

SSDEEP:

98304:mnt/hFhybzXTKoZI2/ZPUpqrL8UmGf11hI07U/eocwHJiE6DfZMsYf1yWf9ttYvB:K+BfBYHcHJY30f7f9b

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3416)
    • Unusual connection from system programs

      • rundll32.exe (PID: 3244)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 3416)
    • Reads settings of System Certificates

      • rundll32.exe (PID: 3244)
    • The process creates files with name similar to system file names

      • WinRAR.exe (PID: 3416)
    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 3416)
    • Reads the Internet Settings

      • rundll32.exe (PID: 3244)
    • Adds/modifies Windows certificates

      • rundll32.exe (PID: 3244)
  • INFO

    • Reads the software policy settings

      • rundll32.exe (PID: 3244)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3416)
    • Reads security settings of Internet Explorer

      • rundll32.exe (PID: 3244)
    • Manual execution by a user

      • rundll32.exe (PID: 3244)
      • reversehub.exe (PID: 3604)
      • reversehub.exe (PID: 2756)
      • HTTPDebuggerUI.exe (PID: 3540)
      • reversehub.exe (PID: 3984)
      • reversehub.exe (PID: 2544)
      • reversehub.exe (PID: 1308)
      • HTTPDebuggerUI.exe (PID: 1852)
    • Create files in a temporary directory

      • rundll32.exe (PID: 3244)
    • Reads the computer name

      • reversehub.exe (PID: 2756)
      • reversehub.exe (PID: 2544)
      • reversehub.exe (PID: 1308)
    • Reads Environment values

      • reversehub.exe (PID: 2756)
      • reversehub.exe (PID: 2544)
      • reversehub.exe (PID: 1308)
    • Checks supported languages

      • reversehub.exe (PID: 2756)
      • reversehub.exe (PID: 1308)
      • HTTPDebuggerUI.exe (PID: 3540)
      • reversehub.exe (PID: 2544)
      • HTTPDebuggerUI.exe (PID: 1852)
    • Reads product name

      • reversehub.exe (PID: 2756)
      • reversehub.exe (PID: 2544)
      • reversehub.exe (PID: 1308)
    • Reads the machine GUID from the registry

      • reversehub.exe (PID: 2756)
      • reversehub.exe (PID: 2544)
      • reversehub.exe (PID: 1308)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
9
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe reversehub.exe no specs reversehub.exe httpdebuggerui.exe no specs reversehub.exe no specs reversehub.exe reversehub.exe httpdebuggerui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1308"C:\Users\admin\Desktop\reversehub\reversehub.exe" C:\Users\admin\Desktop\reversehub\reversehub.exe
explorer.exe
User:
admin
Company:
reversehub.org
Integrity Level:
HIGH
Description:
reversehub Windows Service
Exit code:
0
Version:
9.0.0.12
Modules
Images
c:\users\admin\desktop\reversehub\reversehub.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\version.dll
1852"C:\Users\admin\Desktop\reversehub\HTTPDebuggerUI.exe" C:\Users\admin\Desktop\reversehub\HTTPDebuggerUI.exeexplorer.exe
User:
admin
Company:
reversehub.org
Integrity Level:
MEDIUM
Description:
RTTP Rebugger
Exit code:
0
Version:
9.0.0.12
Modules
Images
c:\users\admin\desktop\reversehub\httpdebuggerui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24542_none_5c0717c7a00ddc6d\gdiplus.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2544"C:\Users\admin\Desktop\reversehub\reversehub.exe" C:\Users\admin\Desktop\reversehub\reversehub.exe
explorer.exe
User:
admin
Company:
reversehub.org
Integrity Level:
HIGH
Description:
reversehub Windows Service
Exit code:
0
Version:
9.0.0.12
Modules
Images
c:\users\admin\desktop\reversehub\reversehub.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\version.dll
2756"C:\Users\admin\Desktop\reversehub\reversehub.exe" C:\Users\admin\Desktop\reversehub\reversehub.exe
explorer.exe
User:
admin
Company:
reversehub.org
Integrity Level:
HIGH
Description:
reversehub Windows Service
Exit code:
0
Version:
9.0.0.12
Modules
Images
c:\users\admin\desktop\reversehub\reversehub.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\version.dll
3244"C:\Windows\system32\rundll32.exe" cryptext.dll,CryptExtOpenCER C:\Users\admin\Desktop\reversehub\RTTP REBUGGER CA for DEBUG ONLY 2.cerC:\Windows\System32\rundll32.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
3416"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\reversehub.rarC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3540"C:\Users\admin\Desktop\reversehub\HTTPDebuggerUI.exe" C:\Users\admin\Desktop\reversehub\HTTPDebuggerUI.exeexplorer.exe
User:
admin
Company:
reversehub.org
Integrity Level:
MEDIUM
Description:
RTTP Rebugger
Exit code:
0
Version:
9.0.0.12
Modules
Images
c:\users\admin\desktop\reversehub\httpdebuggerui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24542_none_5c0717c7a00ddc6d\gdiplus.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
3604"C:\Users\admin\Desktop\reversehub\reversehub.exe" C:\Users\admin\Desktop\reversehub\reversehub.exeexplorer.exe
User:
admin
Company:
reversehub.org
Integrity Level:
MEDIUM
Description:
reversehub Windows Service
Exit code:
3221226540
Version:
9.0.0.12
Modules
Images
c:\users\admin\desktop\reversehub\reversehub.exe
c:\windows\system32\ntdll.dll
3984"C:\Users\admin\Desktop\reversehub\reversehub.exe" C:\Users\admin\Desktop\reversehub\reversehub.exeexplorer.exe
User:
admin
Company:
reversehub.org
Integrity Level:
MEDIUM
Description:
reversehub Windows Service
Exit code:
3221226540
Version:
9.0.0.12
Modules
Images
c:\users\admin\desktop\reversehub\reversehub.exe
c:\windows\system32\ntdll.dll
Total events
8 667
Read events
8 610
Write events
44
Delete events
13

Modification events

(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3416) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\reversehub.rar
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
23
Suspicious files
2
Text files
4
Unknown types
1

Dropped files

PID
Process
Filename
Type
3416WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3416.6972\reversehub\cximagecrt.dllexecutable
MD5:A2FE19B6B766A12017C8BE442AD0CEF2
SHA256:35B71D192854EDC95248F77DEB824F034E903447319459AAF454269650FD51D3
3416WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3416.6972\reversehub\license.rtftext
MD5:E30DD37A2C6C0CA03EBEEA75C23B6A41
SHA256:7C3AE7672FFEECD2FBD64F2105470448B50BDA683D0FAC92619A14C621A54583
3416WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3416.6972\reversehub\drv\Win7\RttpRebuggerSdk64.sysexecutable
MD5:A98A78E8A2752576B7EE30FE8ABF0616
SHA256:33CC9F14EFFFF513FC515322EF288FE9B7B622ECC477BB8DB0456A58D5134C8A
3416WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3416.6972\reversehub\HTTPDebuggerUI.exeexecutable
MD5:D7D0310BFC8DEBDA76E5C9A2D51FB30C
SHA256:C093E677CBF89F26743373CD09B58A27500CD4E103033B767587A90AA40760C0
3416WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3416.6972\reversehub\HTTPDebuggerBrowser.dllexecutable
MD5:4FACBAAB17F633D153A7B53FB483B22F
SHA256:C557B766A00FD4BA6950C08C6133C20E4DD800139A19D271D46D6FEB31EBF870
3416WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3416.6972\reversehub\Dumps\UnknownName\rawdump_77A40000.dllexecutable
MD5:39C0402674E8D43146210F7145EB1C33
SHA256:58B617C2B7124F2C4D16D0C83698E02D8A2FAAC33852E489A23CEBD6BD9B8B88
3416WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3416.6972\reversehub\drv\Win8\RttpRebuggerSdk32.sysexecutable
MD5:FC72F65A95C3109D31B0C7175000A8D8
SHA256:1F5DC9586EB951044F2A92CFF0AA30934582FE014F548B0AB61CEE10CF863934
3416WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3416.6972\reversehub\drv\Win7\RttpRebuggerSdk32.sysexecutable
MD5:95345CEF021028B57BF85DB8A30AD2C6
SHA256:243C14B5E1C49750FD3B4C64E59E0A27A8FFE56B0D7C010BA0661A1EF9E1CD96
3416WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3416.6972\reversehub\nss\libplc4.dllexecutable
MD5:4C579FDC84C02563B39D6EEFE124AC33
SHA256:CF7E003B36930664FB804EC9973FAEB2FE9125F75844737C9536697CB2952471
3416WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3416.6972\reversehub\nss\nssdbm3.dllexecutable
MD5:9AE776DE79CA3EE8899F0526353EC7F8
SHA256:067E7A7FE7A03ACFBB898CC9AD452DF1C66A50E601C282DC49494296C31915F8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3244
rundll32.exe
GET
200
173.222.108.147:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?3941af430fd62041
unknown
unknown
3244
rundll32.exe
GET
304
173.222.108.147:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?00c0310db96741df
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3244
rundll32.exe
173.222.108.147:80
ctldl.windowsupdate.com
Akamai International B.V.
CH
unknown

DNS requests

Domain
IP
Reputation
ctldl.windowsupdate.com
  • 173.222.108.147
  • 173.222.108.210
whitelisted

Threats

No threats detected
No debug info