File name:

USB Network Gate.rar

Full analysis: https://app.any.run/tasks/c5460f2c-8fcd-42b7-a8c2-f7b38e88cb60
Verdict: Malicious activity
Analysis date: March 29, 2025, 21:01:43
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
arch-email
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

7559543300F4CD50EB13B9D5A4CFB822

SHA1:

3B5CDDB0968C111CB29DB7963388DD078207F254

SHA256:

2FE8ADD005F10DA7791F2A36839FCD292C30A648DCF042E283DC2134AE6A6149

SSDEEP:

98304:5fOhnftufSq9HRSnwsYdHBC6dmbyRlCvAI7spJUoJUypElkNAQWb6Lp56sJbjGG/:RbnvpZguBeBZ+6c41OieGlPUs2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • UsbConfig.exe (PID: 7676)
      • UsbConfig.exe (PID: 8176)
    • Reads Internet Explorer settings

      • UsbConfig.exe (PID: 7676)
      • UsbConfig.exe (PID: 8176)
    • Reads the history of recent RDP connections

      • UsbConfig.exe (PID: 8176)
      • UsbConfig.exe (PID: 7676)
    • Reads security settings of Internet Explorer

      • UsbConfig.exe (PID: 8176)
      • UsbConfig.exe (PID: 7676)
    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 6620)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6620)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 6620)
    • Reads the computer name

      • UsbConfig.exe (PID: 7676)
      • UsbService64.exe (PID: 8080)
      • UsbConfig.exe (PID: 8176)
    • Creates files in the program directory

      • UsbConfig.exe (PID: 7676)
    • Checks proxy server information

      • UsbConfig.exe (PID: 7676)
      • UsbConfig.exe (PID: 8176)
    • Manual execution by a user

      • UsbService64.exe (PID: 8080)
      • UsbService64.exe (PID: 8032)
      • UsbConfig.exe (PID: 8176)
      • UsbConfig.exe (PID: 7676)
    • Creates files or folders in the user directory

      • UsbConfig.exe (PID: 7676)
    • Checks supported languages

      • UsbService64.exe (PID: 8080)
      • UsbConfig.exe (PID: 8176)
      • UsbConfig.exe (PID: 7676)
    • Reads the software policy settings

      • UsbConfig.exe (PID: 7676)
      • UsbConfig.exe (PID: 8176)
    • Reads the machine GUID from the registry

      • UsbConfig.exe (PID: 7676)
      • UsbConfig.exe (PID: 8176)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 1094759
UncompressedSize: 2680752
OperatingSystem: Win32
ArchivedFileName: USB Network Gate/appstatico64.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
8
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs usbconfig.exe usbservice64.exe no specs usbservice64.exe conhost.exe no specs usbconfig.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6112C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6620"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\USB Network Gate.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
7592C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
7676"C:\Users\admin\Desktop\USB Network Gate\UsbConfig.exe" C:\Users\admin\Desktop\USB Network Gate\UsbConfig.exe
explorer.exe
User:
admin
Company:
Electronic Team
Integrity Level:
MEDIUM
Description:
USB Network Gate
Exit code:
0
Version:
10.0.2450
Modules
Images
c:\users\admin\desktop\usb network gate\usbconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
8032"C:\Users\admin\Desktop\USB Network Gate\UsbService64.exe" C:\Users\admin\Desktop\USB Network Gate\UsbService64.exeexplorer.exe
User:
admin
Company:
Electronic Team
Integrity Level:
MEDIUM
Description:
USB Network Gate
Exit code:
3221226540
Version:
10.0.2450
Modules
Images
c:\users\admin\desktop\usb network gate\usbservice64.exe
c:\windows\system32\ntdll.dll
8080"C:\Users\admin\Desktop\USB Network Gate\UsbService64.exe" C:\Users\admin\Desktop\USB Network Gate\UsbService64.exe
explorer.exe
User:
admin
Company:
Electronic Team
Integrity Level:
HIGH
Description:
USB Network Gate
Exit code:
1
Version:
10.0.2450
Modules
Images
c:\users\admin\desktop\usb network gate\usbservice64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
8092\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeUsbService64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
8176"C:\Users\admin\Desktop\USB Network Gate\UsbConfig.exe" C:\Users\admin\Desktop\USB Network Gate\UsbConfig.exe
explorer.exe
User:
admin
Company:
Electronic Team
Integrity Level:
MEDIUM
Description:
USB Network Gate
Exit code:
0
Version:
10.0.2450
Modules
Images
c:\users\admin\desktop\usb network gate\usbconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
Total events
7 949
Read events
7 871
Write events
74
Delete events
4

Modification events

(PID) Process:(6620) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6620) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6620) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6620) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\USB Network Gate.rar
(PID) Process:(6620) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6620) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6620) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6620) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6620) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
(PID) Process:(6620) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:size
Value:
80
Executable files
19
Suspicious files
27
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
6620WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6620.42849\USB Network Gate\appstatico64.dllexecutable
MD5:17C833FB6912B34CBEA55281B9C88300
SHA256:F2319106706877DC844EC26FE94EA98C8BC9D268FF0E2DEF054B6E647AAE9963
6620WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6620.42849\USB Network Gate\drv\NT10x64\fusbhub.sysexecutable
MD5:EB7AD68D1CAAC624A2AD279554388D47
SHA256:F51025A97C05711468CCE8D109C95370B7E847B507C870F246AEEB9B927DD2EB
6620WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6620.42849\USB Network Gate\drv\NT10x64\setup_server_ung.exeexecutable
MD5:8098DF53020ED3EEA3136BB688E7DA00
SHA256:D45251FE9FCDC3F539A2C4AE5A2919BF705B9B44F27C84DD2951C41A0033CBB5
6620WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6620.42849\USB Network Gate\drv\NT10x64\sessapart.infbinary
MD5:EAF78C39FEE6925CBDB938D2A34E90C4
SHA256:C0445E520C07136832E2600366931CF89C745971462F1073889ACAEF190D1A41
6620WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6620.42849\USB Network Gate\drv\NT10x64\eusbstub.sysexecutable
MD5:7B9BAA6C28D2FA927551178B4A9CB6FE
SHA256:C83D8EACC0B2F9177DDF250585FCCA1B654DA50224CE46EF324B51881423BB20
6620WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6620.42849\USB Network Gate\drv\NT10x64\vuh.infbinary
MD5:457AAD0CDE717B4734D020EA7E247CE9
SHA256:B5387EFCDE4A971C1932C5B1CFCA08FA4D4D057AEFA2275FEFD52E84694601BA
6620WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6620.42849\USB Network Gate\drv\NT10x64\sessapart.catbinary
MD5:34BDA6B9E03FF959656C19D70CB15506
SHA256:7339F61882174F7C07E8C7E55AB2C793D481EBAE815232DA90B713B894A0FA79
6620WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6620.42849\USB Network Gate\drv\NT10x64\sessapart.sysexecutable
MD5:7F0A31CCF1500E40313AB8EE16D5EB29
SHA256:507D3607407DB2525AFD2CAE6AA05B73C368F5749660A7FE21D6323766A20846
6620WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6620.42849\USB Network Gate\drv\NT10x64\UsbOverTcp.catbinary
MD5:A1889336190807E641C3AEAF738365E9
SHA256:163310EE3EBFECF6044D42B6AF8161F9F4C55FF64B6BC934E997A71A4490B563
6620WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6620.42849\USB Network Gate\drv\NT10x64\UsbStub.infbinary
MD5:5506E37C9246FFAEEE6CE61038C9A5B3
SHA256:02F04A335BC04CD04289B0C6514960BB6ED2939A309BEBF58E76929DECDCB02F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
47
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.145:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7676
UsbConfig.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEQCTi7COYph7T3X5jLalBFyW
unknown
whitelisted
7676
UsbConfig.exe
GET
200
172.64.149.23:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
whitelisted
7884
SIHClient.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7884
SIHClient.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
23.48.23.145:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
6544
svchost.exe
20.190.160.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:137
whitelisted
2112
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2104
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7676
UsbConfig.exe
192.168.100.255:5474
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
  • 51.124.78.146
whitelisted
google.com
  • 216.58.206.78
whitelisted
crl.microsoft.com
  • 23.48.23.145
  • 23.48.23.141
  • 23.48.23.147
  • 23.48.23.177
  • 23.48.23.143
  • 23.48.23.166
  • 23.48.23.173
  • 23.48.23.158
  • 23.48.23.194
whitelisted
login.live.com
  • 20.190.160.130
  • 20.190.160.2
  • 20.190.160.65
  • 20.190.160.64
  • 40.126.32.74
  • 20.190.160.132
  • 40.126.32.72
  • 20.190.160.22
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
client.wns.windows.com
  • 20.198.162.78
whitelisted
cdn.electronic.us
  • 169.150.255.183
  • 169.150.255.181
  • 212.102.56.178
  • 207.211.211.26
  • 195.181.175.41
  • 195.181.170.19
  • 37.19.194.81
  • 195.181.175.40
  • 207.211.211.27
  • 37.19.194.80
  • 195.181.170.18
unknown
ocsp.comodoca.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
ocsp.usertrust.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted

Threats

No threats detected
No debug info