File name:

llegit hub.zip

Full analysis: https://app.any.run/tasks/483a1414-a5b4-4029-8abd-6aa48f2e3539
Verdict: Malicious activity
Analysis date: May 15, 2025, 19:02:15
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
arch-doc
pastebin
crypto-regex
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

208F9D6501FB1ED6FA844551C6D4A77E

SHA1:

48ECD49483C0C91352DA18492B490D2183540D50

SHA256:

680BB934C96DF90C096E0349635E65230E55446F00D65A761D48D4CBC95D2656

SSDEEP:

49152:Io0KjeOnsDrtbJywI3w4HPLjEsDK/IDiSfl4aqAiCTbeNqvARx/yuRK7CUsGbjrE:8KjeOn2rWwqw4HPPbOQtfl4tAizuAryo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • iniuria.exe (PID: 8072)
      • Client.exe (PID: 8104)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • iniuria.exe (PID: 8072)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 7488)
    • Starts itself from another location

      • iniuria.exe (PID: 8072)
    • There is functionality for taking screenshot (YARA)

      • Client.exe (PID: 8104)
    • Connects to unusual port

      • Client.exe (PID: 8104)
    • Found regular expressions for crypto-addresses (YARA)

      • Client.exe (PID: 8104)
  • INFO

    • Checks supported languages

      • iniuria.exe (PID: 8072)
      • Client.exe (PID: 8104)
    • Reads the computer name

      • iniuria.exe (PID: 8072)
      • Client.exe (PID: 8104)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7488)
    • Reads Environment values

      • iniuria.exe (PID: 8072)
      • Client.exe (PID: 8104)
    • Creates files or folders in the user directory

      • iniuria.exe (PID: 8072)
    • Reads the machine GUID from the registry

      • iniuria.exe (PID: 8072)
      • Client.exe (PID: 8104)
    • Disables trace logs

      • Client.exe (PID: 8104)
    • Checks proxy server information

      • Client.exe (PID: 8104)
    • Reads the software policy settings

      • Client.exe (PID: 8104)
      • slui.exe (PID: 7656)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2025:05:13 16:23:14
ZipCRC: 0xf0273518
ZipCompressedSize: 1355447
ZipUncompressedSize: 1624576
ZipFileName: llegit hub/iniuria.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
132
Monitored processes
7
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe iniuria.exe client.exe svchost.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2196C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2392C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7488"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\llegit hub.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
7612C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7656"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
8072"C:\Users\admin\AppData\Local\Temp\Rar$EXa7488.6167\llegit hub\iniuria.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa7488.6167\llegit hub\iniuria.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3
Version:
1.6.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa7488.6167\llegit hub\iniuria.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
8104"C:\Users\admin\AppData\Roaming\SubDir\Client.exe"C:\Users\admin\AppData\Roaming\SubDir\Client.exe
iniuria.exe
User:
admin
Integrity Level:
MEDIUM
Version:
1.6.0
Modules
Images
c:\users\admin\appdata\roaming\subdir\client.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
4 088
Read events
4 064
Write events
24
Delete events
0

Modification events

(PID) Process:(7488) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(7488) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7488) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7488) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\llegit hub.zip
(PID) Process:(7488) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7488) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7488) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7488) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(8072) iniuria.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Pulsar Client Startup
Value:
"C:\Users\admin\AppData\Roaming\SubDir\Client.exe"
(PID) Process:(8104) Client.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Pulsar Client Startup
Value:
"C:\Users\admin\AppData\Roaming\SubDir\Client.exe"
Executable files
5
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
7488WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7488.6167\llegit hub\readmeIMPORTANT.txttext
MD5:D1C2FF4D54107DA09657ED8EDF9648B7
SHA256:D01A95D28D619315AF7AAA068F927FBE6E928896D35F20F017C0D886161FB2CF
7488WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7488.6167\llegit hub\iniuria.exeexecutable
MD5:33FBB1624D14946309AE3425636DE4C2
SHA256:D77E2B0CDB76C0EB4F202A9DC24E9C75D2FE10BCEE3478C7C51308056F17FDF3
7488WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7488.10039\llegit hub\iniuria.exeexecutable
MD5:33FBB1624D14946309AE3425636DE4C2
SHA256:D77E2B0CDB76C0EB4F202A9DC24E9C75D2FE10BCEE3478C7C51308056F17FDF3
7488WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7488.6167\llegit hub\iniuriaNOOUTSIDEINJECTER.dllexecutable
MD5:44C128AF0ED42B7D6B1DBF84AFC1EA49
SHA256:EACCC647145ED7119D7E3A114F18138B54D789991D03F9E0E3564BF8BC74E611
7488WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7488.8625\llegit hub\iniuria.exeexecutable
MD5:33FBB1624D14946309AE3425636DE4C2
SHA256:D77E2B0CDB76C0EB4F202A9DC24E9C75D2FE10BCEE3478C7C51308056F17FDF3
8072iniuria.exeC:\Users\admin\AppData\Roaming\SubDir\Client.exeexecutable
MD5:33FBB1624D14946309AE3425636DE4C2
SHA256:D77E2B0CDB76C0EB4F202A9DC24E9C75D2FE10BCEE3478C7C51308056F17FDF3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
26
DNS requests
16
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.134:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.134:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6480
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6480
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:137
whitelisted
23.48.23.134:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2104
svchost.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
5496
MoUsoCoreWorker.exe
23.48.23.134:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
69.192.161.161:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
69.192.161.161:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
2112
svchost.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.110
whitelisted
crl.microsoft.com
  • 23.48.23.134
  • 23.48.23.139
  • 23.48.23.194
  • 23.48.23.183
  • 23.48.23.191
  • 23.48.23.193
  • 23.48.23.138
  • 23.48.23.181
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 69.192.161.161
  • 2.23.246.101
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 20.190.160.3
  • 40.126.32.76
  • 40.126.32.136
  • 20.190.160.64
  • 20.190.160.65
  • 20.190.160.22
  • 20.190.160.5
  • 20.190.160.17
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
pastebin.com
  • 104.22.68.199
  • 104.22.69.199
  • 172.67.25.94
whitelisted
clothing-lucia.gl.at.ply.gg
  • 147.185.221.26
unknown
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted

Threats

PID
Process
Class
Message
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Online Pastebin Text Storage
2196
svchost.exe
A Network Trojan was detected
MALWARE [ANY.RUN] Suspected domain Associated with Malware Distribution (.ply .gg)
2196
svchost.exe
Potentially Bad Traffic
ET INFO playit .gg Tunneling Domain in DNS Lookup
2196
svchost.exe
Misc activity
ET TA_ABUSED_SERVICES Tunneling Service in DNS Lookup (* .ply .gg)
No debug info