File name:

USB Network Gate.rar

Full analysis: https://app.any.run/tasks/c5460f2c-8fcd-42b7-a8c2-f7b38e88cb60
Verdict: Malicious activity
Analysis date: March 29, 2025, 21:01:43
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
arch-email
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

7559543300F4CD50EB13B9D5A4CFB822

SHA1:

3B5CDDB0968C111CB29DB7963388DD078207F254

SHA256:

2FE8ADD005F10DA7791F2A36839FCD292C30A648DCF042E283DC2134AE6A6149

SSDEEP:

98304:5fOhnftufSq9HRSnwsYdHBC6dmbyRlCvAI7spJUoJUypElkNAQWb6Lp56sJbjGG/:RbnvpZguBeBZ+6c41OieGlPUs2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 6620)
    • Reads the history of recent RDP connections

      • UsbConfig.exe (PID: 7676)
      • UsbConfig.exe (PID: 8176)
    • Reads security settings of Internet Explorer

      • UsbConfig.exe (PID: 7676)
      • UsbConfig.exe (PID: 8176)
    • Reads Microsoft Outlook installation path

      • UsbConfig.exe (PID: 7676)
      • UsbConfig.exe (PID: 8176)
    • Reads Internet Explorer settings

      • UsbConfig.exe (PID: 7676)
      • UsbConfig.exe (PID: 8176)
  • INFO

    • The sample compiled with english language support

      • WinRAR.exe (PID: 6620)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6620)
    • Checks supported languages

      • UsbConfig.exe (PID: 7676)
      • UsbService64.exe (PID: 8080)
      • UsbConfig.exe (PID: 8176)
    • Reads the computer name

      • UsbConfig.exe (PID: 7676)
      • UsbService64.exe (PID: 8080)
      • UsbConfig.exe (PID: 8176)
    • Manual execution by a user

      • UsbConfig.exe (PID: 7676)
      • UsbService64.exe (PID: 8032)
      • UsbService64.exe (PID: 8080)
      • UsbConfig.exe (PID: 8176)
    • Creates files in the program directory

      • UsbConfig.exe (PID: 7676)
    • Checks proxy server information

      • UsbConfig.exe (PID: 7676)
      • UsbConfig.exe (PID: 8176)
    • Reads the software policy settings

      • UsbConfig.exe (PID: 7676)
      • UsbConfig.exe (PID: 8176)
    • Creates files or folders in the user directory

      • UsbConfig.exe (PID: 7676)
    • Reads the machine GUID from the registry

      • UsbConfig.exe (PID: 7676)
      • UsbConfig.exe (PID: 8176)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 1094759
UncompressedSize: 2680752
OperatingSystem: Win32
ArchivedFileName: USB Network Gate/appstatico64.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
8
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs usbconfig.exe usbservice64.exe no specs usbservice64.exe conhost.exe no specs usbconfig.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6112C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6620"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\USB Network Gate.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
7592C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
7676"C:\Users\admin\Desktop\USB Network Gate\UsbConfig.exe" C:\Users\admin\Desktop\USB Network Gate\UsbConfig.exe
explorer.exe
User:
admin
Company:
Electronic Team
Integrity Level:
MEDIUM
Description:
USB Network Gate
Exit code:
0
Version:
10.0.2450
Modules
Images
c:\users\admin\desktop\usb network gate\usbconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
8032"C:\Users\admin\Desktop\USB Network Gate\UsbService64.exe" C:\Users\admin\Desktop\USB Network Gate\UsbService64.exeexplorer.exe
User:
admin
Company:
Electronic Team
Integrity Level:
MEDIUM
Description:
USB Network Gate
Exit code:
3221226540
Version:
10.0.2450
Modules
Images
c:\users\admin\desktop\usb network gate\usbservice64.exe
c:\windows\system32\ntdll.dll
8080"C:\Users\admin\Desktop\USB Network Gate\UsbService64.exe" C:\Users\admin\Desktop\USB Network Gate\UsbService64.exe
explorer.exe
User:
admin
Company:
Electronic Team
Integrity Level:
HIGH
Description:
USB Network Gate
Exit code:
1
Version:
10.0.2450
Modules
Images
c:\users\admin\desktop\usb network gate\usbservice64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
8092\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeUsbService64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
8176"C:\Users\admin\Desktop\USB Network Gate\UsbConfig.exe" C:\Users\admin\Desktop\USB Network Gate\UsbConfig.exe
explorer.exe
User:
admin
Company:
Electronic Team
Integrity Level:
MEDIUM
Description:
USB Network Gate
Exit code:
0
Version:
10.0.2450
Modules
Images
c:\users\admin\desktop\usb network gate\usbconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
Total events
7 949
Read events
7 871
Write events
74
Delete events
4

Modification events

(PID) Process:(6620) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6620) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6620) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6620) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\USB Network Gate.rar
(PID) Process:(6620) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6620) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6620) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6620) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6620) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
(PID) Process:(6620) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:size
Value:
80
Executable files
19
Suspicious files
27
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
6620WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6620.42849\USB Network Gate\appstatico64.dllexecutable
MD5:17C833FB6912B34CBEA55281B9C88300
SHA256:F2319106706877DC844EC26FE94EA98C8BC9D268FF0E2DEF054B6E647AAE9963
6620WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6620.42849\USB Network Gate\drv\NT10x64\sessapart.infbinary
MD5:EAF78C39FEE6925CBDB938D2A34E90C4
SHA256:C0445E520C07136832E2600366931CF89C745971462F1073889ACAEF190D1A41
6620WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6620.42849\USB Network Gate\drv\NT10x64\vuh.infbinary
MD5:457AAD0CDE717B4734D020EA7E247CE9
SHA256:B5387EFCDE4A971C1932C5B1CFCA08FA4D4D057AEFA2275FEFD52E84694601BA
6620WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6620.42849\USB Network Gate\drv\NT10x64\vuhub3.sysexecutable
MD5:0FF399D8C25F1CB0CDFCEB98E5E5709D
SHA256:7883F6B2550B61492EDBB17AEA084CCBE4E66BDB5E595B93404C508A10B6E091
6620WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6620.42849\USB Network Gate\locale\es.tkvbinary
MD5:A10C8CF86914D90F722A109F36FE4C98
SHA256:4A5F7C259FB1280273A565B057B28000B43C67511240523C42D292A51BAB2F84
6620WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6620.42849\USB Network Gate\auth64.dllexecutable
MD5:BA4D1CF5CA020737FC065CB8F280386F
SHA256:AA520CF56E88968132D8A8DF6436684C3F02B8C58D209CFA7EA1400BA3F89E89
6620WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6620.42849\USB Network Gate\drv\NT10x64\eusbstub.sysexecutable
MD5:7B9BAA6C28D2FA927551178B4A9CB6FE
SHA256:C83D8EACC0B2F9177DDF250585FCCA1B654DA50224CE46EF324B51881423BB20
6620WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6620.42849\USB Network Gate\drv\NT10x64\sessapart.sysexecutable
MD5:7F0A31CCF1500E40313AB8EE16D5EB29
SHA256:507D3607407DB2525AFD2CAE6AA05B73C368F5749660A7FE21D6323766A20846
6620WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6620.42849\USB Network Gate\drv\NT10x64\setup_server_ung.exeexecutable
MD5:8098DF53020ED3EEA3136BB688E7DA00
SHA256:D45251FE9FCDC3F539A2C4AE5A2919BF705B9B44F27C84DD2951C41A0033CBB5
6620WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6620.42849\USB Network Gate\drv\NT10x64\fusbhub.sysexecutable
MD5:EB7AD68D1CAAC624A2AD279554388D47
SHA256:F51025A97C05711468CCE8D109C95370B7E847B507C870F246AEEB9B927DD2EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
47
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.145:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
7884
SIHClient.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
NL
binary
407 b
whitelisted
7884
SIHClient.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
NL
binary
419 b
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
7676
UsbConfig.exe
GET
200
172.64.149.23:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
US
binary
1.42 Kb
whitelisted
7676
UsbConfig.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEQCTi7COYph7T3X5jLalBFyW
unknown
binary
2.18 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
23.48.23.145:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
6544
svchost.exe
20.190.160.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:137
whitelisted
2112
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2104
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7676
UsbConfig.exe
192.168.100.255:5474
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
  • 51.124.78.146
whitelisted
google.com
  • 216.58.206.78
whitelisted
crl.microsoft.com
  • 23.48.23.145
  • 23.48.23.141
  • 23.48.23.147
  • 23.48.23.177
  • 23.48.23.143
  • 23.48.23.166
  • 23.48.23.173
  • 23.48.23.158
  • 23.48.23.194
whitelisted
login.live.com
  • 20.190.160.130
  • 20.190.160.2
  • 20.190.160.65
  • 20.190.160.64
  • 40.126.32.74
  • 20.190.160.132
  • 40.126.32.72
  • 20.190.160.22
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
client.wns.windows.com
  • 20.198.162.78
whitelisted
cdn.electronic.us
  • 169.150.255.183
  • 169.150.255.181
  • 212.102.56.178
  • 207.211.211.26
  • 195.181.175.41
  • 195.181.170.19
  • 37.19.194.81
  • 195.181.175.40
  • 207.211.211.27
  • 37.19.194.80
  • 195.181.170.18
unknown
ocsp.comodoca.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
ocsp.usertrust.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted

Threats

No threats detected
No debug info