File name:

Wub.zip

Full analysis: https://app.any.run/tasks/3e40c105-d7ba-40fc-88dc-2e22c629a017
Verdict: Malicious activity
Analysis date: April 17, 2025, 15:03:44
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
autoit
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

ED00BD4050B593B6D2646763A38C90B5

SHA1:

8463EAF04DCD345FA1B2657696E749A2C576CE17

SHA256:

301A365194818156070E8CF5F9EE76F132AD79A1D9D5DC84E1532105FC1E6B42

SSDEEP:

24576:uVdro3e8YGdUV/VT5nucEGDTeyDCZMzo9ZmFRsqShBAi2R516lm:uVdrou8YGdUV/VT5nucHDTeyDCZMzo9u

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • Wub.exe (PID: 7740)
      • Wub.exe (PID: 7816)
      • Wub.exe (PID: 7412)
    • Generic archive extractor

      • WinRAR.exe (PID: 7308)
    • Creates or modifies Windows services

      • Wub.exe (PID: 7816)
    • Changes the Windows auto-update feature

      • Wub.exe (PID: 7816)
    • Changes image file execution options

      • Wub.exe (PID: 7816)
      • Wub.exe (PID: 7412)
  • SUSPICIOUS

    • Modifies existing scheduled task

      • schtasks.exe (PID: 4000)
      • schtasks.exe (PID: 5988)
      • schtasks.exe (PID: 1056)
      • schtasks.exe (PID: 5376)
      • schtasks.exe (PID: 5008)
      • schtasks.exe (PID: 6156)
      • schtasks.exe (PID: 1388)
      • schtasks.exe (PID: 8036)
      • schtasks.exe (PID: 8104)
      • schtasks.exe (PID: 8172)
      • schtasks.exe (PID: 1912)
      • schtasks.exe (PID: 4024)
      • schtasks.exe (PID: 3896)
      • schtasks.exe (PID: 1280)
      • schtasks.exe (PID: 7428)
      • schtasks.exe (PID: 7616)
      • schtasks.exe (PID: 7700)
      • schtasks.exe (PID: 7812)
      • schtasks.exe (PID: 8024)
      • schtasks.exe (PID: 4944)
      • schtasks.exe (PID: 7964)
      • schtasks.exe (PID: 8084)
      • schtasks.exe (PID: 5400)
      • schtasks.exe (PID: 1852)
      • schtasks.exe (PID: 6488)
      • schtasks.exe (PID: 8156)
      • schtasks.exe (PID: 2800)
      • schtasks.exe (PID: 7200)
      • schtasks.exe (PID: 900)
      • schtasks.exe (PID: 720)
    • Creates or modifies Windows services

      • Wub.exe (PID: 7816)
      • Wub.exe (PID: 7412)
    • Application launched itself

      • Wub.exe (PID: 7816)
    • There is functionality for taking screenshot (YARA)

      • Wub.exe (PID: 7816)
  • INFO

    • Reads mouse settings

      • Wub.exe (PID: 7816)
      • Wub.exe (PID: 7412)
    • Manual execution by a user

      • Wub.exe (PID: 7816)
      • Wub.exe (PID: 7740)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7308)
    • Checks supported languages

      • Wub.exe (PID: 7816)
      • Wub.exe (PID: 7412)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 7308)
    • Create files in a temporary directory

      • Wub.exe (PID: 7816)
    • Reads the computer name

      • Wub.exe (PID: 7816)
      • Wub.exe (PID: 7412)
    • The process uses AutoIt

      • Wub.exe (PID: 7816)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2022:01:28 13:58:06
ZipCRC: 0xc1146d1f
ZipCompressedSize: 479059
ZipUncompressedSize: 794752
ZipFileName: Wub.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
192
Monitored processes
66
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe no specs wub.exe no specs wub.exe schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs wub.exe schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
720"C:\WINDOWS\System32\schtasks.exe" /change /tn "Microsoft\Windows\UpdateOrchestrator\USO_Broker_Display" /disableC:\Windows\System32\schtasks.exeWub.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Task Scheduler Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
780\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeschtasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
812\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeschtasks.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
900"C:\WINDOWS\System32\schtasks.exe" /change /tn "Microsoft\Windows\UpdateOrchestrator\UpdateModelTask" /disableC:\Windows\System32\schtasks.exeWub.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Task Scheduler Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1056"C:\WINDOWS\System32\schtasks.exe" /change /tn "Microsoft\Windows\UpdateOrchestrator\Report policies" /disableC:\Windows\System32\schtasks.exeWub.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Scheduler Configuration Tool
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1096\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeschtasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1272\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeschtasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1280"C:\WINDOWS\System32\schtasks.exe" /change /tn "Microsoft\Windows\UpdateOrchestrator\Schedule Scan" /disableC:\Windows\System32\schtasks.exeWub.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Scheduler Configuration Tool
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1388"C:\WINDOWS\System32\schtasks.exe" /change /tn "Microsoft\Windows\UpdateOrchestrator\USO_UxBroker" /disableC:\Windows\System32\schtasks.exeWub.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Scheduler Configuration Tool
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1852"C:\WINDOWS\System32\schtasks.exe" /change /tn "Microsoft\Windows\UpdateOrchestrator\USO_UxBroker" /disableC:\Windows\System32\schtasks.exeWub.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Task Scheduler Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
Total events
5 793
Read events
5 722
Write events
66
Delete events
5

Modification events

(PID) Process:(7308) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(7308) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7308) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7308) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Wub.zip
(PID) Process:(7308) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7308) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7308) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7308) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7308) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(7308) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
Executable files
1
Suspicious files
7
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
7816Wub.exeC:\Users\admin\AppData\Local\Temp\autEABF.tmpbinary
MD5:B6E44B6487FA30BC17ABEE8DBCF82CC9
SHA256:E05CD49495C972BC56C89536ED40F43AFC47A5601CF69ADAB2F684D7E2F04B3F
7816Wub.exeC:\Windows\SysWOW64\GroupPolicy\Machine\Registry.polbinary
MD5:8E1B08222F20E45A3E8DB04C569F9CB7
SHA256:5BB1F21F806938A043563024B13B33D74A2B95B767C5F81BDE8456E9D0413A89
7412Wub.exeC:\Windows\Temp\aut84B.tmpbinary
MD5:1AC691FDD79F8692A85A0A6FB99B4802
SHA256:7E1947BE4292199A16E59052DBA6C746B2235BAD9BD055CCC301DFE8F9B1B750
7412Wub.exeC:\Windows\Temp\7g4o1z2m.tmptext
MD5:B04BCEC7DC7556B020986516FD55180D
SHA256:977466519E4153B8E60DB781294FF53BA529E66325CFA39C6CBA31975DF1DD5D
7816Wub.exeC:\Users\admin\AppData\Local\Temp\autEAE1.tmpbinary
MD5:3CB2A4B882558785B7E42A5911ED466B
SHA256:2A68E7C8F18DB1DED5B42880792C46DFC8D2D22B864A8630BEDF879FA67B8914
7816Wub.exeC:\Users\admin\AppData\Local\Temp\autEAD0.tmpbinary
MD5:1AC691FDD79F8692A85A0A6FB99B4802
SHA256:7E1947BE4292199A16E59052DBA6C746B2235BAD9BD055CCC301DFE8F9B1B750
7308WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7308.4703\Wub.exeexecutable
MD5:585C5000D1A851B295FF295389D7AA1A
SHA256:15FCCF8C018BBBED14664D5A5528CDF087B9032543BE2169D78AB25D141D2B2C
7816Wub.exeC:\Users\admin\AppData\Local\Temp\7q8x1p6p.tmptext
MD5:B04BCEC7DC7556B020986516FD55180D
SHA256:977466519E4153B8E60DB781294FF53BA529E66325CFA39C6CBA31975DF1DD5D
7308WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7308.4703\Wub.initext
MD5:7A7BBE82AA1A7F46AEBE4818800FBC03
SHA256:2E0F9C20004D0987FCA33E68BF952A67E86BD71F55738DD3F979C6959ED5B370
7412Wub.exeC:\Windows\Temp\aut85C.tmpbinary
MD5:3CB2A4B882558785B7E42A5911ED466B
SHA256:2A68E7C8F18DB1DED5B42880792C46DFC8D2D22B864A8630BEDF879FA67B8914
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
12
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
104.124.11.17:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2104
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
MoUsoCoreWorker.exe
104.124.11.17:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
4
System
192.168.100.255:137
whitelisted
6544
svchost.exe
20.190.159.64:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2112
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 104.124.11.17
  • 104.124.11.58
whitelisted
google.com
  • 142.250.185.238
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 20.190.159.64
  • 20.190.159.71
  • 20.190.159.130
  • 20.190.159.23
  • 40.126.31.130
  • 20.190.159.75
  • 40.126.31.3
  • 40.126.31.69
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted

Threats

No threats detected
No debug info