File name:

reversehub.rar

Full analysis: https://app.any.run/tasks/0c922a9c-95c5-404c-b16b-efe821ea5603
Verdict: Malicious activity
Analysis date: April 20, 2024, 09:27:25
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

2FE649F3A5FBDE9AA282E7AF35BF09F5

SHA1:

A304B219B9F60F23BC25F7F053A749906ED06A46

SHA256:

20E1D46A3C5CE3A8663CEA4B4B10E66D11E922EE3BD535C2F76B38436DE0A2FA

SSDEEP:

98304:mnt/hFhybzXTKoZI2/ZPUpqrL8UmGf11hI07U/eocwHJiE6DfZMsYf1yWf9ttYvB:K+BfBYHcHJY30f7f9b

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3416)
    • Unusual connection from system programs

      • rundll32.exe (PID: 3244)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 3416)
    • Reads settings of System Certificates

      • rundll32.exe (PID: 3244)
    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 3416)
    • The process creates files with name similar to system file names

      • WinRAR.exe (PID: 3416)
    • Reads the Internet Settings

      • rundll32.exe (PID: 3244)
    • Adds/modifies Windows certificates

      • rundll32.exe (PID: 3244)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3416)
    • Manual execution by a user

      • rundll32.exe (PID: 3244)
      • reversehub.exe (PID: 3604)
      • reversehub.exe (PID: 2756)
      • HTTPDebuggerUI.exe (PID: 3540)
      • reversehub.exe (PID: 3984)
      • reversehub.exe (PID: 2544)
      • reversehub.exe (PID: 1308)
      • HTTPDebuggerUI.exe (PID: 1852)
    • Reads the software policy settings

      • rundll32.exe (PID: 3244)
    • Reads security settings of Internet Explorer

      • rundll32.exe (PID: 3244)
    • Create files in a temporary directory

      • rundll32.exe (PID: 3244)
    • Reads the computer name

      • reversehub.exe (PID: 2756)
      • reversehub.exe (PID: 2544)
      • reversehub.exe (PID: 1308)
    • Reads the machine GUID from the registry

      • reversehub.exe (PID: 2756)
      • reversehub.exe (PID: 2544)
      • reversehub.exe (PID: 1308)
    • Checks supported languages

      • reversehub.exe (PID: 2756)
      • HTTPDebuggerUI.exe (PID: 3540)
      • reversehub.exe (PID: 2544)
      • reversehub.exe (PID: 1308)
      • HTTPDebuggerUI.exe (PID: 1852)
    • Reads Environment values

      • reversehub.exe (PID: 2756)
      • reversehub.exe (PID: 2544)
      • reversehub.exe (PID: 1308)
    • Reads product name

      • reversehub.exe (PID: 2756)
      • reversehub.exe (PID: 2544)
      • reversehub.exe (PID: 1308)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
9
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe reversehub.exe no specs reversehub.exe httpdebuggerui.exe no specs reversehub.exe no specs reversehub.exe reversehub.exe httpdebuggerui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1308"C:\Users\admin\Desktop\reversehub\reversehub.exe" C:\Users\admin\Desktop\reversehub\reversehub.exe
explorer.exe
User:
admin
Company:
reversehub.org
Integrity Level:
HIGH
Description:
reversehub Windows Service
Exit code:
0
Version:
9.0.0.12
Modules
Images
c:\users\admin\desktop\reversehub\reversehub.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\version.dll
1852"C:\Users\admin\Desktop\reversehub\HTTPDebuggerUI.exe" C:\Users\admin\Desktop\reversehub\HTTPDebuggerUI.exeexplorer.exe
User:
admin
Company:
reversehub.org
Integrity Level:
MEDIUM
Description:
RTTP Rebugger
Exit code:
0
Version:
9.0.0.12
Modules
Images
c:\users\admin\desktop\reversehub\httpdebuggerui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24542_none_5c0717c7a00ddc6d\gdiplus.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2544"C:\Users\admin\Desktop\reversehub\reversehub.exe" C:\Users\admin\Desktop\reversehub\reversehub.exe
explorer.exe
User:
admin
Company:
reversehub.org
Integrity Level:
HIGH
Description:
reversehub Windows Service
Exit code:
0
Version:
9.0.0.12
Modules
Images
c:\users\admin\desktop\reversehub\reversehub.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\version.dll
2756"C:\Users\admin\Desktop\reversehub\reversehub.exe" C:\Users\admin\Desktop\reversehub\reversehub.exe
explorer.exe
User:
admin
Company:
reversehub.org
Integrity Level:
HIGH
Description:
reversehub Windows Service
Exit code:
0
Version:
9.0.0.12
Modules
Images
c:\users\admin\desktop\reversehub\reversehub.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\version.dll
3244"C:\Windows\system32\rundll32.exe" cryptext.dll,CryptExtOpenCER C:\Users\admin\Desktop\reversehub\RTTP REBUGGER CA for DEBUG ONLY 2.cerC:\Windows\System32\rundll32.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
3416"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\reversehub.rarC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3540"C:\Users\admin\Desktop\reversehub\HTTPDebuggerUI.exe" C:\Users\admin\Desktop\reversehub\HTTPDebuggerUI.exeexplorer.exe
User:
admin
Company:
reversehub.org
Integrity Level:
MEDIUM
Description:
RTTP Rebugger
Exit code:
0
Version:
9.0.0.12
Modules
Images
c:\users\admin\desktop\reversehub\httpdebuggerui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24542_none_5c0717c7a00ddc6d\gdiplus.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
3604"C:\Users\admin\Desktop\reversehub\reversehub.exe" C:\Users\admin\Desktop\reversehub\reversehub.exeexplorer.exe
User:
admin
Company:
reversehub.org
Integrity Level:
MEDIUM
Description:
reversehub Windows Service
Exit code:
3221226540
Version:
9.0.0.12
Modules
Images
c:\users\admin\desktop\reversehub\reversehub.exe
c:\windows\system32\ntdll.dll
3984"C:\Users\admin\Desktop\reversehub\reversehub.exe" C:\Users\admin\Desktop\reversehub\reversehub.exeexplorer.exe
User:
admin
Company:
reversehub.org
Integrity Level:
MEDIUM
Description:
reversehub Windows Service
Exit code:
3221226540
Version:
9.0.0.12
Modules
Images
c:\users\admin\desktop\reversehub\reversehub.exe
c:\windows\system32\ntdll.dll
Total events
8 667
Read events
8 610
Write events
44
Delete events
13

Modification events

(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3416) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\reversehub.rar
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
23
Suspicious files
2
Text files
4
Unknown types
1

Dropped files

PID
Process
Filename
Type
3416WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3416.6972\reversehub\drv\Win8\RttpRebuggerSdk32.sysexecutable
MD5:FC72F65A95C3109D31B0C7175000A8D8
SHA256:1F5DC9586EB951044F2A92CFF0AA30934582FE014F548B0AB61CEE10CF863934
3416WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3416.6972\reversehub\Dumps\UnknownName\rawdump_77A40000.dllexecutable
MD5:39C0402674E8D43146210F7145EB1C33
SHA256:58B617C2B7124F2C4D16D0C83698E02D8A2FAAC33852E489A23CEBD6BD9B8B88
3416WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3416.6972\reversehub\HTTPDebuggerBrowser.dllexecutable
MD5:4FACBAAB17F633D153A7B53FB483B22F
SHA256:C557B766A00FD4BA6950C08C6133C20E4DD800139A19D271D46D6FEB31EBF870
3416WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3416.6972\reversehub\Dumps\wow64cpu.dllexecutable
MD5:3AC83046EBD3D5BB31B1C59ABECE1AB5
SHA256:01B167176EC2F751870192B54A795FBD006078F2B5C7E439A59FB1C201C8F07E
3416WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3416.6972\reversehub\drv\Win8\RttpRebuggerSdk64.sysexecutable
MD5:947C624C4BD48F8C66FCD00FC0F947D4
SHA256:2E89606775ED719B9D950AE9D37E819A2567426FBE5C3E0AAD8D86FEC693B67B
3416WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3416.6972\reversehub\cximagecrt.dllexecutable
MD5:A2FE19B6B766A12017C8BE442AD0CEF2
SHA256:35B71D192854EDC95248F77DEB824F034E903447319459AAF454269650FD51D3
3416WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3416.6972\reversehub\drv\Win7\RttpRebuggerSdk32.sysexecutable
MD5:95345CEF021028B57BF85DB8A30AD2C6
SHA256:243C14B5E1C49750FD3B4C64E59E0A27A8FFE56B0D7C010BA0661A1EF9E1CD96
3416WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3416.6972\reversehub\nss\nssckbi.dllexecutable
MD5:44BC840B029AB4D51071E2105F255EF4
SHA256:E2A8FAF01ABB32E7581E777AFEAE9563C731E0A090D92AB30CB1D610B15CA1F5
3416WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3416.6972\reversehub\nss\nssutil3.dllexecutable
MD5:CE30DA9B6A3CDCEA8AC9DED28B9820C5
SHA256:7B06910F6BAA5156B352D7D0474AC92D7DE8497A7D0CBD96C7BAAF172EC20EBB
3416WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3416.6972\reversehub\nss\nssdbm3.dllexecutable
MD5:9AE776DE79CA3EE8899F0526353EC7F8
SHA256:067E7A7FE7A03ACFBB898CC9AD452DF1C66A50E601C282DC49494296C31915F8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3244
rundll32.exe
GET
304
173.222.108.147:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?00c0310db96741df
unknown
unknown
3244
rundll32.exe
GET
200
173.222.108.147:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?3941af430fd62041
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3244
rundll32.exe
173.222.108.147:80
ctldl.windowsupdate.com
Akamai International B.V.
CH
unknown

DNS requests

Domain
IP
Reputation
ctldl.windowsupdate.com
  • 173.222.108.147
  • 173.222.108.210
whitelisted

Threats

No threats detected
No debug info